Unauthenticated full-read SSRF via Twilio integration
High
R
Rocket.Chat
Submitted None
Team Summary
Official summary from Rocket.Chat
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Actions:
Reported by
mokusou
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Server-Side Request Forgery (SSRF)