PT-2024-22768 · Rocket.Chat+1 · Rocket.Chat.Audit+1

Published

2024-03-17

·

Updated

2024-08-13

·

CVE-2024-29151

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rocket.Chat.Audit through 5ad78e8
Description The issue arises because Rocket.Chat.Audit depends on filecachetools, which is not available in PyPI. This situation may lead to potential security risks due to the missing dependency.
Recommendations For Rocket.Chat.Audit through 5ad78e8, consider removing or replacing the dependency on filecachetools to mitigate potential risks until a proper fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

CVE-2024-29151

Affected Products

Rocket.Chat.Audit
Filecachetools