CVE-2024-46936

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Sep 25, 2024
Updated: Sep 26, 2024

Summary

CVE-2024-46936 is a vulnerability affecting Rocket.Chat versions 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, and earlier. Hackers can manipulate the UpdateOTRAck method to craft and send ephemeral messages under the guise of any user they target, resulting in message forgery and impersonation. This issue poses a significant threat to the security and privacy of communication in Rocket.Chat systems. Users are strongly advised to upgrade to a patched version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Rocket Chat

Affected Vendors

  • Rocket.Chat Technologies Corp.