CVE Vulnerabilities

CVE-2020-29594

Published: Dec 30, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.

Affected Software

NameVendorStart VersionEnd Version
Rocket.chatRocket.chat*0.74.4 (excluding)
Rocket.chatRocket.chat1.0.0 (including)1.3.4 (excluding)
Rocket.chatRocket.chat2.0.0 (including)2.4.13 (excluding)
Rocket.chatRocket.chat3.0.0 (including)3.7.3 (excluding)
Rocket.chatRocket.chat3.8.0 (including)3.8.3 (excluding)
Rocket.chatRocket.chat3.9.0 (including)3.9.1 (excluding)

References