Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbitrary user by sending a single HTTP POST with MongoDB query operators to /oauth/token. The Rocket.Chat OAuth2 server does not validate that grant parameters are strings before forwarding them to findOne({...}) against the oauth_apps and oauth_access_tokens collections, so an attacker substitutes {"$ne": null} for client_id, client_secret, and refresh_token and receives a freshly minted {access_token, refresh_token} pair bound to whichever user's refresh token Mongo returned first. The resulting access token is a first-class bearer credential against the full /api/v1/* surface as that user. By iterating with $nin / $regex operators the attacker walks the entire oauth_access_tokens collection, collecting one fresh access token per user per request. If any matched token belongs to an admin, the stolen bearer gives full admin API access (including Apps-Engine app installation, i.e. server-side code execution). No account, credentials, userId, or prior interaction with the instance are required. This vulnerability is fixed in 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11.
The OAuth2 server in Rocket.Chat does not validate whether request parameters (client_id, client_secret, refresh_token) are strings before passing them to the findOne({...}) function on oauth_apps and oauth_access_tokens collections. An attacker substitutes MongoDB operators, such as {"$ne": null}, in place of these parameters, resulting in the first matching token being returned from the database and generating a new pair of {access_token, refresh_token} linked to a given user's account. By iterating with $nin and $regex operators, an attacker can traverse the entire oauth_access_tokens collection and gather fresh access tokens for all users. The obtained token is a valid Bearer-type credential against the entire /api/v1/* API surface and does not require any prior authentication credentials or interaction with the instance.
An attacker can hijack accounts of any users, and in case of obtaining an administrator token — gain full access to the administrative API, including installing applications through Apps-Engine, which leads to remote code execution on the server side (RCE).
Rocket.Chat should be updated to version 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, or 7.10.11 (depending on the branch in use). Details are available in the official security advisory from the vendor at https://github.com/RocketChat/Rocket.Chat/security/advisories/GHSA-8p25-fm45-pjrw
Rocket.Chat in versions earlier than 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N