A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://hackerone.com/reports/1886954 |
History
Fri, 06 Sep 2024 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 30 Aug 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Rocket.chat
Rocket.chat rocket.chat |
|
Weaknesses | CWE-918 | |
CPEs | cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* | |
Vendors & Products |
Rocket.chat
Rocket.chat rocket.chat |
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2024-08-05T04:26:06.959Z
Updated: 2024-09-06T16:32:07.303Z
Reserved: 2024-06-28T01:04:08.821Z
Link: CVE-2024-39713
Vulnrichment
Updated: 2024-08-08T20:16:07.075Z
NVD
Status : Modified
Published: 2024-08-05T05:15:39.297
Modified: 2024-09-06T17:35:12.380
Link: CVE-2024-39713
Redhat
No data.