CVE-2024-46935: High severity rocket.chat livechat vulnerability
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46935?
CVE-2024-46935 is classified as a denial of service (DoS) vulnerability.
How do I fix CVE-2024-46935?
To fix CVE-2024-46935, update Rocket.Chat to a version later than 6.12.0 or apply the necessary patches.
What versions of Rocket.Chat are affected by CVE-2024-46935?
Rocket.Chat versions 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier are affected by CVE-2024-46935.
What causes CVE-2024-46935 vulnerability?
CVE-2024-46935 is caused by an issue in the message parser that crashes the workspace when processing messages with specific characters.
Is there a workaround for CVE-2024-46935?
Currently, the only effective workaround for CVE-2024-46935 is to upgrade to a patched version of Rocket.Chat.