PT-2021-15267 · Unknown · Rocket.Chat

Sonarsource

·

Published

2021-08-09

·

Updated

2022-10-25

·

CVE-2021-22910

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rocket.Chat server versions prior to 3.13.2 Rocket.Chat server versions prior to 3.12.4 Rocket.Chat server versions prior to 3.11.4
Description A sanitization issue exists in the Rocket.Chat server that allows queries to an endpoint, potentially resulting in a NoSQL injection and leading to remote code execution (RCE).
Recommendations For versions prior to 3.13.2, update to version 3.13.2 or later. For versions prior to 3.12.4, update to version 3.12.4 or later. For versions prior to 3.11.4, update to version 3.11.4 or later.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-22910

Affected Products

Rocket.Chat