You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I would like to report a potential issue with Rocket.Chat (versions 4.2.0 and 4.3.0) on Windows.
When a user switches profiles (for example, by transitioning to a domain GPO account), all active Windows application sessions are terminated except for Rocket.Chat sessions.
This behavior is problematic because the new user profile can directly access the messages from the previous session without needing to log in again. This poses a security and data privacy risk.
If I am mistaken about this behavior or the version details, please accept my apologies in advance.
I kindly ask you to look into this issue to address the behavior and improve the application's security in such cases.
Thank you in advance for your feedback.
The text was updated successfully, but these errors were encountered:
Hello,
I would like to report a potential issue with Rocket.Chat (versions 4.2.0 and 4.3.0) on Windows.
When a user switches profiles (for example, by transitioning to a domain GPO account), all active Windows application sessions are terminated except for Rocket.Chat sessions.
This behavior is problematic because the new user profile can directly access the messages from the previous session without needing to log in again. This poses a security and data privacy risk.
If I am mistaken about this behavior or the version details, please accept my apologies in advance.
I kindly ask you to look into this issue to address the behavior and improve the application's security in such cases.
Thank you in advance for your feedback.
The text was updated successfully, but these errors were encountered: