Rocket.Chat is an open-source fully customizable communications platform developed in JavaScript. In Rocket.Chat before versions 3.11.3, 3.12.2, and 3.13 an issue with certain regular expressions could lead potentially to Denial of Service. This was fixed in versions 3.11.3, 3.12.2, and 3.13.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://docs.rocket.chat/guides/security/security-updates | vendor advisory |
https://securitylab.github.com/advisories/GHSL-2020-310-redos-Rocket.Chat/ | third party advisory exploit |
https://github.com/RocketChat/Rocket.Chat/releases/tag/3.11.3 | third party advisory release notes |
https://github.com/RocketChat/Rocket.Chat/commit/4a0dce973e37ec3f56ca2231d6030511dbdd094c | third party advisory patch |