Insufficient Password Entropy in Rocket.Chat Mobile
CVE-2024-42027

Currently unrated

Key Information:

Vendor
CVE Published:
7 October 2024

What is CVE-2024-42027?

The Rocket.Chat Mobile app exhibited a significant vulnerability due to insufficient entropy in its end-to-end encrypted (E2EE) password generation. This weakness permits attackers to potentially crack users' passwords if they possess the necessary time and computational resources. The flaw affects all versions prior to 4.5.1, necessitating prompt updates to ensure robust security measures are in place.

References

Timeline

  • Vulnerability published

.