Loading HuntDB...

Mute User can disclose private channel members to unauthorized users

Medium
R
Rocket.Chat
Submitted None

Team Summary

Official summary from Rocket.Chat

A vulnerability has been identified in Rocket.Chat, where the ACL checks in the Slash Command /mute occur after checking whether a user is a member of a given channel, leaking private channel members to unauthorized users. This allows authenticated users to enumerate whether a username is a member of a channel that they do not have access to.

Reported by gronke

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Information Disclosure