A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: hackerone
Published: 2021-08-09T12:27:46
Updated: 2024-08-03T18:58:26.282Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22910
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-08-09T13:15:07.120
Modified: 2024-11-21T05:50:53.800
Link: CVE-2021-22910
Redhat
No data.