Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-75575

PUBLISHED 29.08.2026

CNA: VulnCheck

Rocket.Chat Missing DDP Rate Limit on the sendForgotPasswordEmail Meteor Method

Обновлено: 29.08.2026
Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may invoke it as often as it likes. The method is reachable over DDP and over the HTTP route POST /api/v1/method.callAnon/sendForgotPasswordEmail, and it triggers a password reset message for any address that matches an account. With no DDPRateLimiter rule registered for it, a caller can drive an unbounded volume of reset mail at a chosen address from the deployment's own mail sender, and can probe addresses at scale: the method answers true for an address with no account and for a successful send, but false when the address belongs to an account that authenticates through an external provider and Accounts_AllowPasswordChangeForOAuthUsers is off, so repeated calls distinguish that class of account. Later versions register a rule permitting ten calls per minute per client address.

CWE

Идентификатор Описание
CWE-204 The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
CWE-307 The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.

CVSS

Оценка Severity Версия Базовый вектор
6.9 MEDIUM 4.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
5.3 MEDIUM 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Доп. Информация

Product Status

Rocket.Chat
Product: Rocket.Chat
Vendor: RocketChat
Default status: unaffected
Версии:
Затронутые версии Статус
Наблюдалось в версиях от 0 до 7.10.15 affected
Наблюдалось в версиях от 8.0.0 до 8.1.8 affected
Наблюдалось в версиях от 8.2.0 до 8.2.8 affected
Наблюдалось в версиях от 8.3.0 до 8.3.8 affected
Наблюдалось в версиях от 8.4.0 до 8.4.6 affected
Наблюдалось в версиях от 8.5.0 до 8.5.3 affected
Наблюдалось в версиях от 8.6.0 до 8.6.2 affected
Наблюдалось в версиях от 8.7.0 до 8.7.2 affected
Наблюдалось в версиях от 8.8.0-rc.0 до 8.8.0 affected
 

Ссылки

CISA ADP Vulnrichment

Обновлено: 25.08.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
none yes partial 2.0.3 25.08.2026

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.