GHSA-99gj-9798-gpx5
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
A cleartext transmission of sensitive information exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 relating to Oauth tokens by having the permission "view-full-other-user-info", this could cause an oauth token leak in the product.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 20, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.