TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2023-28316

CRITICAL
9.8

Beschreibung

A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an attacker to maintain access to a compromised account even after 2FA is enabled.

CVE Details

CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht5/9/2023
Zuletzt geandert1/28/2025
Quellenvd
Honeypot-Sichtungen0

Betroffene Produkte

rocket.chat:rocket.chat

Schwachen (CWE)

CWE-384CWE-384

Referenzen

https://hackerone.com/reports/992280(af854a3a-2127-422b-91ae-364da2661108)

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.