PT-2024-32286 · Unknown · Rocket.Chat

Published

2024-09-24

·

Updated

2024-09-30

·

CVE-2024-46935

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Rocket.Chat versions 6.12.0 through 6.7.8 and earlier
Description The issue allows attackers to craft messages with specific characters, potentially crashing the workspace due to a problem in the message parser. This can lead to a denial of service (DoS).
Recommendations For Rocket.Chat versions 6.12.0 through 6.7.8 and earlier, as a temporary workaround, consider restricting the ability to send messages with specific characters until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-46935
GHSA-6375-PG5J-8WPH

Affected Products

Rocket.Chat