Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue on Rocket.Chat (versions 4.2.0 and 4.3.0) During User Profile Switching on Windows #35634

Closed
oueddadidou opened this issue Mar 27, 2025 · 1 comment

Comments

@oueddadidou
Copy link

Hello,

I would like to report a potential issue with Rocket.Chat (versions 4.2.0 and 4.3.0) on Windows.

When a user switches profiles (for example, by transitioning to a domain GPO account), all active Windows application sessions are terminated except for Rocket.Chat sessions.

This behavior is problematic because the new user profile can directly access the messages from the previous session without needing to log in again. This poses a security and data privacy risk.

If I am mistaken about this behavior or the version details, please accept my apologies in advance.

I kindly ask you to look into this issue to address the behavior and improve the application's security in such cases.

Thank you in advance for your feedback.

@julio-rocketchat
Copy link
Member

Hi @oueddadidou. We no longer support the aforementioned versions. You can check the supported versions here: https://docs.rocket.chat/docs/version-durability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants