CVE-2024-46936: High severity rocket.chat livechat vulnerability
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-46936?
CVE-2024-46936 is considered a moderate severity vulnerability due to its potential for message forgery and impersonation.
How do I fix CVE-2024-46936?
To fix CVE-2024-46936, you should update Rocket.Chat to version 6.12.0 or later to mitigate the vulnerability.
What kind of attack is CVE-2024-46936 associated with?
CVE-2024-46936 is associated with a message forgery and impersonation attack that allows attackers to send ephemeral messages as other users.
Which versions of Rocket.Chat are affected by CVE-2024-46936?
Rocket.Chat versions prior to 6.12.0, including 6.11.2, 6.10.5, and earlier, are affected by CVE-2024-46936.
How can attackers exploit CVE-2024-46936?
Attackers can exploit CVE-2024-46936 by abusing the UpdateOTRAck method to send messages as if they were any chosen user.