Vulnerabilities > CVE-2024-39713 - Server-Side Request Forgery (SSRF) vulnerability in Rocket.Chat

047910
CVSS 8.6 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
rocket-chat
CWE-918

Summary

A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.

Vulnerable Configurations

Part Description Count
Application
Rocket.Chat
762

Common Weakness Enumeration (CWE)