RULE(RULE ID:338479)

Rule General Information
Release Date: 2024-10-22
Rule Name: Rocket Chat Server-Side Request Forgery Vulnerability (CVE-2024-39713)
Severity:
CVE ID:
Rule Protection Details
Description: A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, Others
Reference: https://hackerone.com/reports/1886954
Solutions
Refer to the announcement or patch by the vendor: https://github.com/RocketChat/Rocket.Chat/releases/tag/6.10.2