CVE-2022-35249: Rocket.chat
Medium severity, CVSS 4.3. EPSS: 0.8% chance of exploitation in the next 30 days.
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
Affected products
- Rocket.chat Rocket.chat: before 5.0 (fixed in 5.0)
Published 2022-09-23. Last modified 2026-06-17.