Rocketchat

Rocket.Chat

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 24.06.2026 21:16:54
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, in the visitors.info endpoint, https://developer.rocket.chat/apidocs/get-visitor-information-by...

  • EPSS 0.22%
  • Veröffentlicht 24.06.2026 21:16:54
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat does not revoke OAuth bearer or refresh tokens when a user is deactivated. A deacti...

  • EPSS 0.12%
  • Veröffentlicht 24.06.2026 21:16:54
  • Zuletzt bearbeitet 25.06.2026 16:16:35

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement component in packages/gazzodown renders user-controlled src values directly into <a href> and <img src> attributes without protocol sa...

  • EPSS 0.15%
  • Veröffentlicht 24.06.2026 21:16:54
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML service provider implementation silently skips both SAML Response and Assert...

  • EPSS 0.22%
  • Veröffentlicht 24.06.2026 21:16:54
  • Zuletzt bearbeitet 25.06.2026 16:16:35

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.10.12, Rocket.Chat allows users deactivated through users.deactivateIdle to keep using already-issued ...

  • EPSS 0.31%
  • Veröffentlicht 24.06.2026 21:16:53
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, an unauthenticated network attacker obtains a valid Rocket.Chat OAuth access token for an arbit...

  • EPSS 0.45%
  • Veröffentlicht 24.06.2026 21:16:53
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's SAML integration does not verify the signature on inbound LogoutRequest messages....

  • EPSS 0.21%
  • Veröffentlicht 24.06.2026 21:16:53
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's sendFileMessage DDP method passes the entire attacker-supplied file object into U...

  • EPSS 0.29%
  • Veröffentlicht 24.06.2026 21:16:53
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.10.11, Rocket.Chat's CAS login handler forwards the client-supplied options.cas.credentialToken value ...

  • EPSS 0.32%
  • Veröffentlicht 24.06.2026 21:08:01
  • Zuletzt bearbeitet 25.06.2026 14:19:40

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, the POST /api/v1/fingerprint REST endpoint enforces authentication (authRequired: true) but performs no...