RocketChat kayıtları
rocketchat üreticisine ait 3 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %33,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1391 Use of Weak Credentials1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
3 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
30İzleyin | CVE-2024-46936İstismar yok | Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. | Yüksek7,5 | — | %0,4 | 24 Eyl 2024 |
26İzleyin | CVE-2024-42027İstismar yok | The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they havrocket.chat · mobile · CWE-1391 | Orta6,7 | — | %0,5 | 7 Eki 2024 |
24İzleyin | CVE-2017-1000054İstismar yok | Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.rocketchat · rocket.chat · CWE-79 | Orta6,1 | — | %0,7 | 17 Tem 2017 |
- CVE-2024-4693630İzleyin
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue.
YüksekCVSS 7,5İstismar yokEPSS %024 Eyl 2024
- CVE-2024-4202726İzleyin
The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they hav
OrtaCVSS 6,7İstismar yokEPSS %1rocket.chat · mobile7 Eki 2024
- CVE-2017-100005424İzleyin
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.
OrtaCVSS 6,1İstismar yokEPSS %1rocketchat · rocket.chat17 Tem 2017