CVE-2024-39713

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
References
Link Resource
https://hackerone.com/reports/1886954 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*

History

30 Aug 2024, 15:47

Type Values Removed Values Added
First Time Rocket.chat
Rocket.chat rocket.chat
References () https://hackerone.com/reports/1886954 - () https://hackerone.com/reports/1886954 - Issue Tracking, Third Party Advisory
CPE cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*
CWE CWE-918

05 Aug 2024, 12:41

Type Values Removed Values Added
Summary
  • (es) Server-Side Request Forgery (SSRF) afecta al endpoint del webhook Twilio de Rocket.Chat antes de la versión 6.10.1.

05 Aug 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-05 05:15

Updated : 2024-09-06 17:35


NVD link : CVE-2024-39713

Mitre link : CVE-2024-39713

CVE.ORG link : CVE-2024-39713


JSON object : View

Products Affected

rocket.chat

  • rocket.chat
CWE
CWE-918

Server-Side Request Forgery (SSRF)