CVE-2021-22886
26.03.2021, 19:15
Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.
Vendor | Product | Version |
---|---|---|
rocket.chat | rocket.chat | 𝑥 < 3.8.8 |
rocket.chat | rocket.chat | 3.9.0 ≤ 𝑥 < 3.9.7 |
rocket.chat | rocket.chat | 3.10.0 ≤ 𝑥 < 3.10.5 |
rocket.chat | rocket.chat | 3.11.0:rc0 |
rocket.chat | rocket.chat | 3.11.0:rc1 |
rocket.chat | rocket.chat | 3.11.0:rc2 |
rocket.chat | rocket.chat | 3.11.0:rc3 |
rocket.chat | rocket.chat | 3.11.0:rc4 |
rocket.chat | rocket.chat | 3.11.0:rc5 |
rocket.chat | rocket.chat | 3.11.0:rc6 |
rocket.chat | rocket.chat | 3.11.0:rc7 |
𝑥
= Vulnerable software versions
References