An information disclosure vulnerability exists in the Rocket.Chat server fixed v3.13, v3.12.2 & v3.11.3 that allowed email addresses to be disclosed by enumeration and validation checks.
| Software | From | Fixed in |
|---|---|---|
| rocket.chat / rocket.chat | - | 3.11.3 |
| rocket.chat / rocket.chat | 3.12.3 | 3.12.3.x |
| rocket.chat / rocket.chat | 3.12.4 | 3.12.4.x |
| rocket.chat / rocket.chat | 3.12.0 | 3.12.2 |
| rocket.chat / rocket.chat | 3.12.5 | 3.12.5.x |