CVE-2021-32832
Summary
| CVE | CVE-2021-32832 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-08-30 21:15:00 UTC |
| Updated | 2021-09-08 13:42:00 UTC |
| Description | Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13. |
Risk And Classification
Problem Types: CWE-400
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rocket.chat | Rocket.chat | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release 3.11.3 · RocketChat/Rocket.Chat · GitHub | MISC | github.com | |
| GHSL-2020-310: ReDoS (Regular Expression Denial of Service) in Rocket Chat - CVE-2021-32832 | GitHub Security Lab | CONFIRM | securitylab.github.com | |
| Security fixes and updates - Rocket.Chat Docs | MISC | docs.rocket.chat | |
| Bump version to 3.11.3 · RocketChat/Rocket.Chat@4a0dce9 · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.