Medium severity5.3NVD Advisory· Published Jan 8, 2021· Updated Jun 17, 2026
CVE-2020-28208
CVE-2020-28208
Description
An email address enumeration vulnerability exists in the password reset function of Rocket.Chat through 3.9.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*range: <=3.9.1
- (no CPE)range: <=3.9.1
- Rocket.Chat/Rocket.Chatdescription
Patches
Vulnerability mechanics
References
8- packetstormsecurity.com/files/160845/Rocket.Chat-3.7.1-Email-Address-Enumeration.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.openwall.com/lists/oss-security/2021/01/07/1nvdExploitMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/01/08/1nvdExploitMailing ListThird Party Advisory
- www.openwall.com/lists/oss-security/2021/01/13/1nvdExploitMailing ListThird Party Advisory
- trovent.github.io/security-advisories/TRSA-2010-01/TRSA-2010-01.txtnvdExploitThird Party Advisory
- trovent.io/security-advisory-2010-01nvdExploitThird Party Advisory
- seclists.org/fulldisclosure/2021/Jan/32nvdBroken LinkMailing ListThird Party Advisory
- seclists.org/fulldisclosure/2021/Jan/43nvdBroken LinkMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.