NA

CVE-2023-28316

Published: 09/05/2023 Updated: 17/05/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are not invalidated upon activating 2FA. This could potentially allow an malicious user to maintain access to a compromised account even after 2FA is enabled.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rocket.chat rocket.chat -