CVE Vulnerabilities

CVE-2020-29594

Published: Dec 30, 2020 | Modified: Jan 04, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.

Affected Software

Name Vendor Start Version End Version
Rocket.chat Rocket.chat * 0.74.4 (excluding)
Rocket.chat Rocket.chat 1.0.0 (including) 1.3.4 (excluding)
Rocket.chat Rocket.chat 2.0.0 (including) 2.4.13 (excluding)
Rocket.chat Rocket.chat 3.0.0 (including) 3.7.3 (excluding)
Rocket.chat Rocket.chat 3.8.0 (including) 3.8.3 (excluding)
Rocket.chat Rocket.chat 3.9.0 (including) 3.9.1 (excluding)

References