CVE Vulnerabilities

CVE-2022-35246

Published: Sep 23, 2022 | Modified: Jun 29, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to access.

Affected Software

Name Vendor Start Version End Version
Rocket.chat Rocket.chat * 4.7.5 (excluding)
Rocket.chat Rocket.chat 4.8.0 (including) 4.8.2 (excluding)

References