CVE-2024-42027: Rocket.chat Mobile

Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.

The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.

Affected products

Published 2024-10-07. Last modified 2026-06-17.