CVE Vulnerabilities

CVE-2024-46935

Published: Sep 25, 2024 | Modified: Sep 26, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.

Affected Software

Name Vendor Start Version End Version
Rocket.chat Rocket.chat * 6.7.9 (excluding)
Rocket.chat Rocket.chat 6.8.0 (including) 6.8.7 (excluding)
Rocket.chat Rocket.chat 6.9.0 (including) 6.9.7 (excluding)
Rocket.chat Rocket.chat 6.10.0 (including) 6.10.6 (excluding)
Rocket.chat Rocket.chat 6.11.0 (including) 6.11.3 (excluding)
Rocket.chat Rocket.chat 6.12.0 (including) 6.12.0 (including)
Rocket.chat Rocket.chat 6.12.0-rc1 (including) 6.12.0-rc1 (including)
Rocket.chat Rocket.chat 6.12.0-rc2 (including) 6.12.0-rc2 (including)
Rocket.chat Rocket.chat 6.12.0-rc3 (including) 6.12.0-rc3 (including)
Rocket.chat Rocket.chat 6.12.0-rc4 (including) 6.12.0-rc4 (including)
Rocket.chat Rocket.chat 6.12.0-rc5 (including) 6.12.0-rc5 (including)
Rocket.chat Rocket.chat 6.12.0-rc6 (including) 6.12.0-rc6 (including)

References