Back to Database
Status published
Medium
CVE-2020-28208
An email address enumeration vulnerability exists in the password reset...
Vulnerability Description
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-28208
Credits & Attribution
No credits recorded in the NVD database.
References
- https://trovent.io/security-advisory-2010-01
- http://www.openwall.com/lists/oss-security/2021/01/07/1
- http://packetstormsecurity.com/files/160845/Rocket.Chat-3.7.1-Email-Address-Enumeration.html
- http://www.openwall.com/lists/oss-security/2021/01/08/1
- https://trovent.github.io/security-advisories/TRSA-2010-01/TRSA-2010-01.txt
- http://seclists.org/fulldisclosure/2021/Jan/32
- http://www.openwall.com/lists/oss-security/2021/01/13/1
- http://seclists.org/fulldisclosure/2021/Jan/43
More from rocket.chat
View All →CVE-2025-7974
rocket.chat Incorrect Authorization Information Disclosure Vulnerability
Low
3.7
CVE-2020-29594
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x...
Critical
9.8
CVE-2020-26763
The Rocket.Chat desktop application 2.17.11 opens external links without user...
High
7.5
CVE-2020-15926
Rocket.Chat through 3.4.2 allows XSS where an attacker can send...
Medium
6.1
CVE-2019-17220
Rocket.Chat before 2.1.0 allows XSS via a URL on a...
Medium
6.1
Affected Vendor
rocket.chat
View all reports →Affected Software
rocket.chat
Vulnerable Versions:
0
Timeline
Official Publish:
January 8th, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.