Skip to content

Security Issue on Rocket.Chat (versions 4.2.0 and 4.3.0) During User Profile Switching on Windows #35634

@oueddadidou

Description

@oueddadidou

Hello,

I would like to report a potential issue with Rocket.Chat (versions 4.2.0 and 4.3.0) on Windows.

When a user switches profiles (for example, by transitioning to a domain GPO account), all active Windows application sessions are terminated except for Rocket.Chat sessions.

This behavior is problematic because the new user profile can directly access the messages from the previous session without needing to log in again. This poses a security and data privacy risk.

If I am mistaken about this behavior or the version details, please accept my apologies in advance.

I kindly ask you to look into this issue to address the behavior and improve the application's security in such cases.

Thank you in advance for your feedback.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions