A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://hackerone.com/reports/1886954 |
|
History
Fri, 06 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Aug 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rocket.chat
Rocket.chat rocket.chat |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rocket.chat
Rocket.chat rocket.chat |
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: hackerone
Published: 2024-08-05T04:26:06.959Z
Updated: 2024-09-06T16:32:07.303Z
Reserved: 2024-06-28T01:04:08.821Z
Link: CVE-2024-39713
Updated: 2024-08-08T20:16:07.075Z
Status : Modified
Published: 2024-08-05T05:15:39.297
Modified: 2024-09-06T17:35:12.380
Link: CVE-2024-39713
No data.