Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-42149 Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00108}

epss

{'score': 0.00117}


Wed, 25 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Rocketchat
Rocketchat rocket.chat
CPEs cpe:2.3:a:rocketchat:rocket.chat:*:*:*:*:*:*:*:*
Vendors & Products Rocketchat
Rocketchat rocket.chat
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 24 Sep 2024 19:00:00 +0000

Type Values Removed Values Added
Description Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and before is vulnerable to a message forgery / impersonation issue. Attackers can abuse the UpdateOTRAck method to send ephemeral messages as if they were any other user they choose.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-03-25T16:38:15.382Z

Reserved: 2024-09-15T00:00:00.000Z

Link: CVE-2024-46936

cve-icon Vulnrichment

Updated: 2024-09-25T17:24:21.513Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-25T01:15:44.700

Modified: 2024-09-26T13:32:02.803

Link: CVE-2024-46936

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.