CVE-2017-1000054: XSS
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000054?
CVE-2017-1000054 is classified as a medium severity vulnerability due to its potential for causing cross-site scripting (XSS) in Rocket.Chat.
How do I fix CVE-2017-1000054?
To remediate CVE-2017-1000054, update Rocket.Chat to a version that is not affected by this vulnerability, specifically a version above 0.57.2.
What is the impact of CVE-2017-1000054 on Rocket.Chat users?
The impact of CVE-2017-1000054 allows attackers to execute arbitrary JavaScript code in the context of the user's session, which can lead to data theft or account compromise.
Which versions of Rocket.Chat are affected by CVE-2017-1000054?
CVE-2017-1000054 affects all Rocket.Chat versions from 0.8.0 up to and including 0.57.1.
Are there any workarounds for CVE-2017-1000054 if I cannot upgrade?
While upgrading is the best solution, minimizing markdown link usage in messages could serve as a temporary workaround to reduce exposure to CVE-2017-1000054.