-
Notifications
You must be signed in to change notification settings - Fork 11k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
fix security patch regression #1990
Comments
We should have a blacklist of IPs and domains for the previews |
This is tagged security, but there is no description of the bug. How does this affect users? |
If you have a web service running on the same machine as Rocket.Chat, that does't have password, and a user sends a message with a URL like https://localhost:3000 the system will do a HTTP GET on that address and display the title of the response. |
👍 or for the security researcher types .... vulnerability : bot port scanner against the underlying server or virtualization host Original discovery credit goes to @sinteur (Radically Open Security) |
Recent changes have caused regression.
The text was updated successfully, but these errors were encountered: