CVE-2024-46935
HIGHDescription
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.
Is your site exposed to CVE-2024-46935?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Affected Products
| Vendor | Product |
|---|---|
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
| rocket.chat | rocket.chat |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-46935? +
How severe is CVE-2024-46935? +
What products are affected by CVE-2024-46935? +
How do I check if I'm vulnerable to CVE-2024-46935? +
Related Vulnerabilities
In Rocket.Chat <8.3.0, <8.2.1, <8.1.2, <8.0.3, <7.13.5, <7.12.6, <7.11.6, and <7.10.9, a NoSQL injection vulnerability can lead to account takeover …
A Server-Side Request Forgery (SSRF) affects Rocket.Chat's Twilio webhook endpoint before version 6.10.1.
rocket.chat Incorrect Authorization Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of rocket.chat. …
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to DOM-based Cross-site Scripting (XSS). Attackers may be able …
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier allows stored XSS in the description and release notes of the …
The Electron desktop application of Rocket.Chat through 6.3.4 allows stored XSS via links in an uploaded file, related to failure …