Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 26 Sep 2024 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rocket.chat
Rocket.chat rocket.chat |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:6.12.0:-:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:6.12.0:rc1:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:6.12.0:rc2:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:6.12.0:rc3:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:6.12.0:rc4:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:6.12.0:rc5:*:*:*:*:*:* cpe:2.3:a:rocket.chat:rocket.chat:6.12.0:rc6:*:*:*:*:*:* |
|
| Vendors & Products |
Rocket.chat
Rocket.chat rocket.chat |
|
| Metrics |
cvssV3_1
|
Tue, 24 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2024-09-24T00:00:00.000Z
Updated: 2025-03-25T16:20:43.536Z
Reserved: 2024-09-15T00:00:00.000Z
Link: CVE-2024-46935
Updated: 2024-09-24T19:11:05.611Z
Status : Modified
Published: 2024-09-25T01:15:44.650
Modified: 2025-03-25T17:16:10.917
Link: CVE-2024-46935
No data.