Loading HuntDB...

Improper Access Control - Generic

Low
R
Rocket.Chat
Submitted None

Team Summary

Official summary from Rocket.Chat

A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a compromised account even after 2FA is enabled.

Reported by priyank_parmar

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic