CVE-2021-22892
CVE-2021-22892
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
27 May 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
Affected products
n/a · Rocket.Chat serverWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://hackerone.com/reports/1089116