Vulnerabilidades em RocketChat

19 resultados
Análise Vexday

RocketChat apresenta volume moderado com 17 CVEs, dos quais 5 são críticos e 12 foram publicados nos últimos 90 dias, indicando descoberta ativa de vulnerabilidades. Embora nenhuma esteja sob exploração documentada em KEV, a concentração em falhas de autenticação (CWE-287) e o padrão recente de divulgações sugerem vigilância contínua na gestão de patches.

CVE-2021-32832MEDIUMReDOS in Rocket.ChatEPSS 1.6%CVE-2026-28514CRITICALRocket.Chat: Users can login with any password via the EE ddp-streamer-serviceEPSS 0.5%CVE-2026-45677HIGHRocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoSEPSS 0.5%CVE-2026-30831HIGHRocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamerEPSS 0.3%CVE-2026-55762HIGHRocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` EndpointEPSS 0.3%CVE-2026-45689CRITICALRocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATOEPSS 0.3%CVE-2026-23477HIGHRocket.Chat Unauthorized Access to OAuth App DetailsEPSS 0.3%CVE-2026-55666CRITICALRocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuthEPSS 0.3%CVE-2026-45688CRITICALRocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session HijackEPSS 0.3%CVE-2026-30833MEDIUMRocket.Chat: NoSQL injection in the EE ddp-streamer-serviceEPSS 0.3%CVE-2026-55759HIGHRocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replayEPSS 0.2%CVE-2026-49278MEDIUMRocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor ImpersonationEPSS 0.2%CVE-2026-49277LOWRocket.Chat: OAuth access and refresh tokens remain valid after account deactivationEPSS 0.2%CVE-2026-45757LOWRocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokensEPSS 0.2%CVE-2026-45687HIGHRocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessageEPSS 0.2%CVE-2026-46423CRITICALRocket.Chat: SAML signature validation skipped when IdP certificate field is emptyEPSS 0.1%CVE-2026-47733MEDIUMRocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown imagesEPSS 0.1%CVE-2026-72918MEDIUMRocket.Chat: Insecure implementation of websocket notificationsEPSS CVE-2026-72919MEDIUMRocket.Chat: Broken Access Control in channels.convertToTeam Allows Unauthorized Conversion of Public Channels into TeamsEPSS