Critical severity9.8NVD Advisory· Published Aug 9, 2021· Updated Jun 17, 2026
CVE-2021-22910
CVE-2021-22910
Description
A sanitization vulnerability exists in Rocket.Chat server versions <3.13.2, <3.12.4, <3.11.4 that allowed queries to an endpoint which could result in a NoSQL injection, potentially leading to RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rocket.chat:rocket.chat:*:*:*:*:*:*:*:*range: <3.11.4
- (no CPE)range: <3.13.2, <3.12.4, <3.11.4
- Rocket.Chat/Rocket.Chat serverdescription
Patches
Vulnerability mechanics
References
2- hackerone.com/reports/1130874nvdExploitMailing ListThird Party Advisory
- blog.sonarsource.com/nosql-injections-in-rocket-chat/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.