Junglewise Threat Intelligence

CVE-2024-46935: Rocket.Chat message parser denial of service

CVE-2024-46935 · Severity: low · CVSS 3.1 · Published 2024-09-25

Technologies: Rocket.Chat. Vendors: npm, Rocket.Chat.

Executive brief

Rocket.Chat, a widely-used team communication and collaboration platform, contains a vulnerability in its message parsing logic that can be exploited to crash the workspace. An attacker can craft specially-formatted messages containing specific characters that cause the message parser to consume excessive resources, resulting in a denial of service that disrupts all users on the affected instance.

Technical details

The vulnerability exists in Rocket.Chat's message parser component (@rocket.chat/message-parser), which fails to efficiently handle messages containing excessive symbols or specific character sequences. An unauthenticated remote attacker can send a crafted message that triggers catastrophic performance degradation in the parser, consuming significant CPU or memory resources and causing the workspace to become unresponsive or crash. The root cause is related to CWE-400 (uncontrolled resource consumption) in the message parsing logic. The fix was merged in PR #33227 and is available in Rocket.Chat 6.12.1 and later, as well as in message-parser version 0.31.30 and above.

Affected products

  • Rocket.Chat Rocket.Chat 6.12.0, 6.11.2, 6.10.5, 6.9.6, 6.8.6, 6.7.8, and earlier
  • Rocket.Chat message-parser before 0.31.30

Timeline

  • 2024-09-25: disclosed: Vulnerability publicly disclosed
  • 2024-09-25: patched: Fix released in Rocket.Chat 6.12.1 and message-parser 0.31.30

References

Related threats