CVE-2023-23917
CVSS V2 None
CVSS V3 None
Description
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack vector also may increase the impact of XSS to RCE which is dangerous for self-hosted users as well.
Overview
- CVE ID
- CVE-2023-23917
- Assigner
- support@hackerone.com
- Vulnerability Status
- Analyzed
- Published Version
- 2023-02-23T20:15:13
- Last Modified Date
- 2023-03-03T16:35:22
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* | 1 | OR | 5.2.0 |
References
Reference URL | Reference Tags |
---|---|
https://hackerone.com/reports/1631258 | Permissions Required |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-23917 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23917 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 05:23:28 | Added to TrackCVE | |||
2023-04-17 05:23:30 | Weakness Enumeration | new |