This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis →
Q1What is this vulnerability? (Essence + Consequences)
🚨 **Essence**: A Pre-Auth Blind NoSQL Injection in Rocket.Chat. 💥 **Consequences**: Attackers can hijack accounts via leaked password reset tokens.…
⚡ **Threshold**: **LOW**. No authentication or authorization is required to trigger the injection. It is a **Pre-Auth** vulnerability, making it extremely easy to exploit for any internet-facing instance.
Q6Is there a public Exp? (PoC/Wild Exploitation)
💣 **Public Exploits**: **YES**. Multiple PoCs are available on GitHub (e.g., by CsEnox, optionalCTF, ChrisPritchard). Automated scripts exist for account takeover and RCE. 📥 **Exploit-DB**: ID 49960.
Q7How to self-check? (Features/Scanning)
🔍 **Self-Check**:
1. Check Rocket.Chat version (3.11-3.13).
2. Scan for the `getPasswordPolicy` endpoint.
3. Test if the password reset token parameter accepts JSON injection payloads (like `$regex`).
4.…
🩹 **Fix Status**: **YES**. The vulnerability was published in May 2021. Users must upgrade to a patched version of Rocket.Chat immediately. 📢 **Reference**: SonarSource blog and official CVE details.
Q9What if no patch? (Workaround)
🚧 **Workaround (If No Patch)**:
1. **Block Access**: Restrict access to the `/api/v1/method.getPasswordPolicy` endpoint via WAF or firewall.
2.…
🔥 **Urgency**: **CRITICAL**. Since it allows **Unauthenticated RCE**, it is a high-priority target for attackers. Immediate patching or mitigation is required to prevent full server compromise. 🏃♂️💨