{"id":"CVE-2021-22911","details":"A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenticated NoSQL injection, resulting potentially in RCE.","modified":"2026-08-07T15:15:10.719223Z","published":"2021-05-27T12:15:08.153Z","references":[{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/162997/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.html"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/163419/Rocket.Chat-3.12.1-NoSQL-Injection-Code-Execution.html"},{"type":"EVIDENCE","url":"https://blog.sonarsource.com/nosql-injections-in-rocket-chat"},{"type":"EVIDENCE","url":"https://hackerone.com/reports/1130721"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rocketchat/rocket.chat","events":[{"introduced":"62aa68d7166db80813bb1e92f4642e9b6b61471c"},{"last_affected":"0b789f790fabc38888c3eaaf4207c9d77c2cc0e2"}],"database_specific":{"cpe":["cpe:2.3:a:rocket.chat:rocket.chat:3.11.0:-:*:*:*:*:*:*","cpe:2.3:a:rocket.chat:rocket.chat:3.12.0:-:*:*:*:*:*:*","cpe:2.3:a:rocket.chat:rocket.chat:3.13.0:-:*:*:*:*:*:*"],"extracted_events":[{"introduced":"3.11.0-NA"},{"last_affected":"3.11.0-NA"},{"introduced":"3.12.0-NA"},{"last_affected":"3.12.0-NA"},{"introduced":"3.13.0-NA"},{"last_affected":"3.13.0-NA"}],"source":"CPE_STRING"}}],"versions":["3.11.0-NA","3.12.0-NA","3.13.0-NA","3.12.3","3.13.0","3.12.2","3.12.1","3.12.0","3.11.1","3.11.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22911.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}