Vulnerabilities/

Denial of service in rocket chat message parser

Severity:
Medium

Description

Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.

Recommendation

Update the @rocket.chat/message-parser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@rocket.chat/message-parser
Anything's wrong? Let us know Last updated on September 26, 2024