← back
CVE-2021-22910CWE-75

CVE-2021-22910

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.3%
exploitation probability
2.3%top 19% of all CVEs
observed exploitation
nono source reports it
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
Affected products
n/a · Rocket.Chat server