CVE Vulnerabilities

CVE-2024-46935

Published: Sep 25, 2024 | Modified: Mar 25, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.

Affected Software

NameVendorStart VersionEnd Version
Rocket.chatRocket.chat*6.7.9 (excluding)
Rocket.chatRocket.chat6.8.0 (including)6.8.7 (excluding)
Rocket.chatRocket.chat6.9.0 (including)6.9.7 (excluding)
Rocket.chatRocket.chat6.10.0 (including)6.10.6 (excluding)
Rocket.chatRocket.chat6.11.0 (including)6.11.3 (excluding)
Rocket.chatRocket.chat6.12.0 (including)6.12.0 (including)
Rocket.chatRocket.chat6.12.0-rc1 (including)6.12.0-rc1 (including)
Rocket.chatRocket.chat6.12.0-rc2 (including)6.12.0-rc2 (including)
Rocket.chatRocket.chat6.12.0-rc3 (including)6.12.0-rc3 (including)
Rocket.chatRocket.chat6.12.0-rc4 (including)6.12.0-rc4 (including)
Rocket.chatRocket.chat6.12.0-rc5 (including)6.12.0-rc5 (including)
Rocket.chatRocket.chat6.12.0-rc6 (including)6.12.0-rc6 (including)

References