First published: Mon Jul 05 2021(Updated: )
The Rocket.Chat desktop application 2.17.11 opens external links without user interaction.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rocket.chat Rocket.chat | =2.17.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-26763.
The severity of CVE-2020-26763 is high with a score of 7.5.
CVE-2020-26763 allows external links to be opened without user interaction in the Rocket.Chat desktop application version 2.17.11.
To fix CVE-2020-26763, you should update to a version of the Rocket.Chat desktop application that has addressed the issue.
More information about CVE-2020-26763 can be found in the GitHub pull request linked here: https://github.com/RocketChat/Rocket.Chat.Electron/pull/1710