CVE-2022-35250

4.3MEDIUM

A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to view Direct messages without appropriate permissions.

Published: 9/23/2022Updated: 5/22/2025

Description

A privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to view Direct messages without appropriate permissions.

AI AnalysisPowered by AI

Affected Products

rocket.chatrocket.chat

References