CVE-2021-22910
09.08.2021, 13:15
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
Vendor | Product | Version |
---|---|---|
rocket.chat | rocket.chat | 𝑥 < 3.11.4 |
rocket.chat | rocket.chat | 3.12.0 ≤ 𝑥 < 3.12.4 |
rocket.chat | rocket.chat | 3.13.0 ≤ 𝑥 < 3.13.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration