HomeDefault status
unaffected
8.4.0 (semver) before 8.4.0
affected
Description
An open redirect vulnerability in Rocket.Chat versions prior to 8.4.0 allows users to be redirected to arbitrary URLs by manipulating parameters within a SAML endpoint.
Problem types
Product status
8.4.0 (semver) before 8.4.0
References
github.com/RocketChat/Rocket.Chat/pull/38994