The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
| Software | From | Fixed in |
|---|---|---|
| beyondtrust / privileged_remote_access | 24.2.2 | 24.2.4.x |
| beyondtrust / privileged_remote_access | 24.3.1 | 24.3.4 |
| beyondtrust / privileged_remote_access | 25.1.1 | 25.1.1.x |
| beyondtrust / remote_support | 24.2.2 | 24.2.4.x |
| beyondtrust / remote_support | 24.3.1 | 24.3.4 |
| beyondtrust / remote_support | 25.1.1 | 25.1.1.x |