CVE-2021-22886
Published Mar 26, 2021
Last updated 4 years ago
Overview
- Description
- Rocket.Chat before 3.11, 3.10.5, 3.9.7, 3.8.8 is vulnerable to persistent cross-site scripting (XSS) using nested markdown tags allowing a remote attacker to inject arbitrary JavaScript in a message. This flaw leads to arbitrary file read and RCE on Rocket.Chat desktop app.
- Source
- support@hackerone.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 6.1
- Impact score
- 2.7
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 4.3
- Impact score
- 2.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:N/I:P/A:N
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86A30DEE-F0BD-42BD-8BE7-EAFC4EB83A94", "versionEndExcluding": "3.8.8" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A5B4CA06-527F-4600-A11A-ABFA54D754C8", "versionEndExcluding": "3.9.7", "versionStartIncluding": "3.9.0" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D9EFC543-2F10-4521-9814-ABBD237364EB", "versionEndExcluding": "3.10.5", "versionStartIncluding": "3.10.0" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:rc0:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "894B212B-12E9-49D0-9DCC-A8DA2BE98FCD" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:rc1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B996994C-FEC5-4524-94F4-E8F7CD666BC7" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:rc2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "506868F8-3FEE-478E-BAA2-889C53A79977" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:rc3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "49553F24-2CC0-48E6-BA55-4CE0283C1E6A" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:rc4:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C4B247DC-ECB0-4859-8F6D-6CAA2C01B57E" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:rc5:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B3962CCC-17F4-4F4B-AE82-A53DB5ED19A5" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:rc6:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AA4771F7-A143-44C9-8FED-B9111C22D058" }, { "criteria": "cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:rc7:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6CA36B0C-3A4D-44EA-BAB8-A9B2D7F672D2" } ], "operator": "OR" } ] } ]