Summary: | net-im/rocketchat-desktop-bin: link preview XSS (CVE-2020-8291) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED INVALID | ||
Severity: | minor | CC: | nowa |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://github.com/RocketChat/Rocket.Chat/pull/19854 | ||
Whiteboard: | B4 [ebuild] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
![]() ![]() ![]() ![]() (In reply to John Helmert III from comment #0) > CVE-2020-8291: > > A link preview rendering issue in Rocket.Chat versions before 3.9 could lead > to potential XSS attacks. > > Contrary to the CVE description, patch is in 3.10 onward. Please bump. I think this applies to the Rocket.Chat server: https://github.com/RocketChat/Rocket.Chat/releases (not packaged) And not to the Rocket.Chat desktop client: https://github.com/RocketChat/Rocket.Chat.Electron (which doesn't have a version newer then 3.5.7) Ah, sorry! Invalid then |