CVE-2022-35246 | Rocket.Chat up to 4.7.4/4.8.1 Meteor Server getS3FileUrl injection (EUVD-2022-38138)
A vulnerability was found in Rocket.Chat up to 4.7.4/4.8.1. It has been rated as problematic. This issue affects the function getS3FileUrl of the component Meteor Server. The manipulation leads to injection.
The identification of this vulnerability is CVE-2022-35246. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.