9.8
CVE-2020-29594
- EPSS 0.49%
- Veröffentlicht 30.12.2020 07:15:12
- Zuletzt bearbeitet 21.11.2024 05:24:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Rocket.Chat before 0.74.4, 1.x before 1.3.4, 2.x before 2.4.13, 3.x before 3.7.3, 3.8.x before 3.8.3, and 3.9.x before 3.9.1 mishandles SAML login.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rocket.Chat ≫ Rocket.Chat Version < 0.74.4
Rocket.Chat ≫ Rocket.Chat Version >= 1.0.0 < 1.3.4
Rocket.Chat ≫ Rocket.Chat Version >= 2.0.0 < 2.4.13
Rocket.Chat ≫ Rocket.Chat Version >= 3.0.0 < 3.7.3
Rocket.Chat ≫ Rocket.Chat Version >= 3.8.0 < 3.8.3
Rocket.Chat ≫ Rocket.Chat Version >= 3.9.0 < 3.9.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.49% | 0.65 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|