Mute User can disclose private channel members to unauthorized users
Medium
R
Rocket.Chat
Submitted None
Team Summary
Official summary from Rocket.Chat
A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a username is a member of a channel that they do not have access to.
Actions:
Reported by
gronke
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Disclosure