PT-2020-17208 · Rocket.Chat · Rocket.Chat

Published

2020-12-30

·

Updated

2021-01-04

·

CVE-2020-29594

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions prior to 0.74.4 Rocket.Chat versions 1.x prior to 1.3.4 Rocket.Chat versions 2.x prior to 2.4.13 Rocket.Chat versions 3.x prior to 3.7.3 Rocket.Chat versions 3.8.x prior to 3.8.3 Rocket.Chat versions 3.9.x prior to 3.9.1
Description The issue is related to the mishandling of SAML login.
Recommendations For Rocket.Chat versions prior to 0.74.4, update to version 0.74.4 or later. For Rocket.Chat versions 1.x prior to 1.3.4, update to version 1.3.4 or later. For Rocket.Chat versions 2.x prior to 2.4.13, update to version 2.4.13 or later. For Rocket.Chat versions 3.x prior to 3.7.3, update to version 3.7.3 or later. For Rocket.Chat versions 3.8.x prior to 3.8.3, update to version 3.8.3 or later. For Rocket.Chat versions 3.9.x prior to 3.9.1, update to version 3.9.1 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-29594

Affected Products

Rocket.Chat