PT-2021-18239 · Hedgedoc · Hedgedoc

Davidmehren

+1

·

Published

2021-04-26

·

Updated

2022-08-03

·

CVE-2021-29475

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: HedgeDoc versions prior to 1.5.0
Description: The issue affects HedgeDoc, an open-source collaborative markdown editor, where an attacker can receive arbitrary files from the file system when exporting a note to PDF. This exploit requires the attacker's ability to modify a note and affects all instances with PDF export enabled. The impact is significant, as the attacker can read the HedgeDoc config.json file and other files on the filesystem, potentially accessing sensitive information, database credentials, and OAuth secrets.
Recommendations: For versions prior to 1.5.0, upgrade to version 1.5.0 to resolve the issue. As a temporary workaround, consider starting the HedgeDoc instance with CMD ALLOW PDF EXPORT=false or set "allowPDFExport": false in config.json to mitigate this issue.

Fix

SSRF

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2021-29475
GHSA-PXXG-PX9V-6QF3

Affected Products

Hedgedoc