CVE-2024-46936
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Sep 25, 2024
Updated: Sep 26, 2024
Summary
CVE-2024-46936 is a vulnerability affecting Rocket.Chat versions 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, and earlier. Hackers can manipulate the UpdateOTRAck method to craft and send ephemeral messages under the guise of any user they target, resulting in message forgery and impersonation. This issue poses a significant threat to the security and privacy of communication in Rocket.Chat systems. Users are strongly advised to upgrade to a patched version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Rocket Chat
Affected Vendors
- Rocket.Chat Technologies Corp.