Description
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.
Recommendation
Update the @rocket.chat/message-parser package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.31.30
- Patched version(s): 0.31.30
References
Could your website be exposed too?
SmartScanner can check your website for Denial of service in rocket chat message parser and gives you actionable findings to investigate.
Start a free scanRelated Issues
- s3-url-parser vulnerable to Denial of Service via regexes component - CVE-2024-25355
- domain-suffix RegEx Denial of Service - CVE-2024-25354
- Handling untrusted input can result in a crash, leading to loss of availability / denial of service - CVE-2024-30253
- parse-uri Regular expression Denial of Service (ReDoS) - CVE-2024-36751


