CVE-2023-23917

Published Feb 23, 2023

Last updated 21 days ago

Overview

Description
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an attacker to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This attack vector also may increase the impact of XSS to RCE which is dangerous for self-hosted users as well.
Source
support@hackerone.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

support@hackerone.com
CWE-77
nvd@nist.gov
CWE-1321
134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-1321

Social media

Hype score
Not currently trending

Configurations