漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it directly to translateMessage() without checking Meteor.userId() or verifying room membership. Any authenticated DDP user can read the content of any message by ID from any room (private channels, DMs, E2EE rooms) by calling this method.
CVSS Information
N/A
Vulnerability Type
访问控制不恰当
Vulnerability Title
Rocket.Chat 安全漏洞
Vulnerability Description
Rocket.Chat是Rocket.Chat公司的一个聊天软件。 Rocket.Chat 8.5.0之前版本、8.4.2之前版本、8.3.4之前版本、8.2.4之前版本、8.1.5之前版本、8.0.5之前版本、7.13.8之前版本和7.10.12之前版本存在安全漏洞,该漏洞源于autoTranslate.translateMessage DDP方法接受客户端提供的IMessage对象并直接传递给translateMessage()而不检查Meteor.userId()或验证房间成员身份,可能导致任何经过
CVSS Information
N/A
Vulnerability Type
N/A