Description
Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier is vulnerable to denial of service (DoS). Attackers who craft messages with specific characters may crash the workspace due to an issue in the message parser.
Recommendation
Update the @rocket.chat/message-parser package to the latest compatible version. Followings are version details:
- Affected version(s): < 0.31.30
- Patched version(s): 0.31.30
References
Related Issues
- s3-url-parser vulnerable to Denial of Service via regexes component - CVE-2024-25355
- domain-suffix RegEx Denial of Service - CVE-2024-25354
- Handling untrusted input can result in a crash, leading to loss of availability / denial of service - CVE-2024-30253
- parse-uri Regular expression Denial of Service (ReDoS) - CVE-2024-36751
You might also like:
- Tags:
- npm
- @rocket.chat/message-parser
Anything's wrong? Let us know Last updated on September 26, 2024


