Critical severity9.8NVD Advisory· Published May 27, 2021· Updated Jun 17, 2026
CVE-2021-22911
CVE-2021-22911
Description
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:-:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:-:*:*:*:*:*:*
- cpe:2.3:a:rocket.chat:rocket.chat:3.12.0:-:*:*:*:*:*:*
- cpe:2.3:a:rocket.chat:rocket.chat:3.13.0:-:*:*:*:*:*:*
- (no CPE)range: 3.11, 3.12, 3.13
- Rocket.Chat/Rocket.Chat serverdescription
Patches
Vulnerability mechanics
References
4- packetstormsecurity.com/files/162997/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/163419/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.htmlnvdExploitThird Party AdvisoryVDB Entry
- blog.sonarsource.com/nosql-injections-in-rocket-chatnvdExploitThird Party Advisory
- hackerone.com/reports/1130721nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.