CVE-2022-32219 - CVE House
Back to Database
Status published Unknown CVE-2022-32219

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed...

Vulnerability Description

An information disclosure vulnerability exists in Rocket.Chat <v4.7.5 which allowed the "users.list" REST endpoint gets a query parameter from JSON and runs Users.find(queryFromClientSide). This means virtually any authenticated user can access any data (except password hashes) of any user authenticated.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-32219

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Rocket.Chat
Vulnerable Versions:
fixed in 4.7.5>

Timeline

Official Publish: September 23rd, 2022
Last Modified: May 22nd, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)