CVE-2023-23917

CVSS V2 None CVSS V3 None
Description
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack vector also may increase the impact of XSS to RCE which is dangerous for self-hosted users as well.
Overview
  • CVE ID
  • CVE-2023-23917
  • Assigner
  • support@hackerone.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-02-23T20:15:13
  • Last Modified Date
  • 2023-03-03T16:35:22
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* 1 OR 5.2.0
References
Reference URL Reference Tags
https://hackerone.com/reports/1631258 Permissions Required
History
Created Old Value New Value Data Type Notes
2023-04-17 05:23:28 Added to TrackCVE
2023-04-17 05:23:30 Weakness Enumeration new