AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-32220

MEDIUM · CVSS 6.5 EPSS 0.83%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2022-09-23 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-32220
Severity
MEDIUM
CVSS
6.5
EPSS
0.83%

Original NVD Description

An information disclosure vulnerability exists in Rocket.Chat <v5 due to the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.

Related CVEs

Other vulnerabilities affecting the same vendor(s)