What the vulnerability does

01Description

An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

Key dates

02Disclosure timeline

September 23, 2022 CVE published
May 22, 2025 Record updated