Site icon API Security Blog

Rocket.Chat Information Disclosure Vulnerability (CNVD-2022-69164)

Rocket.Chat is a set of open source team chat software. Rocket.Chat suffers from an information disclosure vulnerability that stems from the presence of an explicit transmission of sensitive information related to Oauth tokens, resulting in the leakage of oauth tokens in the product. An attacker could use this vulnerability to access sensitive files.Read More

Exit mobile version