Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
rocket.chat vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-28359
A NoSQL injection vulnerability has been identified in the listEmojiCustom method call within Rocket.Chat. This can be exploited by unauthenticated users when there is at least one custom emoji uploaded to the Rocket.Chat instance. The vulnerability causes a delay in the server r...
Rocket.chat Rocket.chat
NA
CVE-2023-23911
An improper access control vulnerability exists prior to v6 that could allow an malicious user to break the E2E encryption of a chat room by a user changing the group key of a chat room.
Rocket.chat Rocket.chat
NA
CVE-2023-23917
A prototype pollution vulnerability exists in Rocket.Chat server <5.2.0 that could allow an malicious user to a RCE under the admin account. Any user can create their own server in your cloud and become an admin so this vulnerability could affect the cloud infrastructure. This...
Rocket.chat Rocket.chat
668
VMScore
CVE-2020-29594
Rocket.Chat prior to 0.74.4, 1.x prior to 1.3.4, 2.x prior to 2.4.13, 3.x prior to 3.7.3, 3.8.x prior to 3.8.3, and 3.9.x prior to 3.9.1 mishandles SAML login.
Rocket.chat Rocket.chat
384
VMScore
CVE-2020-15926
Rocket.Chat up to and including 3.4.2 allows XSS where an attacker can send a specially crafted message to a channel or in a direct message to the client which results in remote code execution on the client side.
Rocket.chat Rocket.chat
NA
CVE-2022-30124
An improper authentication vulnerability exists in Rocket.Chat Mobile App <4.14.1.22788 that allowed an attacker with physical access to a mobile device to bypass local authentication (PIN code).
Rocket.chat Rocket.chat
NA
CVE-2022-35246
A NoSQL-Injection information disclosure vulnerability vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 in the getS3FileUrl Meteor server method that can disclose arbitrary file upload URLs to users that should not be able to access.
Rocket.chat Rocket.chat
NA
CVE-2022-35247
A information disclosure vulnerability exists in Rocket.chat <v5, <v4.8.2 and <v4.7.5 where the lack of ACL checks in the getRoomRoles Meteor method leak channel members with special roles to unauthorized clients.
Rocket.chat Rocket.chat
NA
CVE-2022-35248
A improper authentication vulnerability exists in Rocket.Chat <v5, <v4.8.2 and <v4.7.5 that allowed two factor authentication can be bypassed when telling the server to use CAS during login.
Rocket.chat Rocket.chat
NA
CVE-2022-35249
A information disclosure vulnerability exists in Rocket.Chat <v5 where the getUserMentionsByChannel meteor server method discloses messages from private channels and direct messages regardless of the users access permission to the room.
Rocket.chat Rocket.chat
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-3400
deserialization
CVE-2024-21788
CVE-2023-42433
CVE-2024-21841
CVE-2024-22095
local file inclusion
memory leak
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
NEXT »