CVE-2024-46936
EUVD-2024-4214925.09.2024, 01:15
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| rocketchat | rocket.chat | 6.12.0 ≤ 𝑥 < 6.12.1 | ADP |
| rocketchat | rocket.chat | 6.11.0 ≤ 𝑥 ≤ 6.11.2 | ADP |
| rocketchat | rocket.chat | 6.10.0 ≤ 𝑥 ≤ 6.10.5 | ADP |
| rocketchat | rocket.chat | 6.9.0 ≤ 𝑥 ≤ 6.9.6 | ADP |
| rocketchat | rocket.chat | 6.8.0 ≤ 𝑥 ≤ 6.8.6 | ADP |
| rocketchat | rocket.chat | 𝑥 ≤ 6.7.8 | ADP |