CVE-2024-39713 is a high-severity Server-Side Request Forgery (SSRF) vulnerability impacting Rocket.Chat's Twilio webhook endpoint in versions prior to 6.10.1. This vulnerability allows an unauthenticated attacker to make arbitrary requests from the server, potentially leading to information disclosure (CVSS 8.6, High). While there is no evidence of active exploitation or Metasploit modules, a Nuclei template exists, indicating potential for exploitation. Community discussion and media coverage are currently minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 6.10.1CPE matchmatch criteria | cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* | ||
>= 6.10.1, < 6.10.1CPE match | cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.