PT-2021-18239 · Hedgedoc · Hedgedoc
Davidmehren
+1
·
Published
2021-04-26
·
Updated
2022-08-03
·
CVE-2021-29475
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
HedgeDoc versions prior to 1.5.0
Description:
The issue affects HedgeDoc, an open-source collaborative markdown editor, where an attacker can receive arbitrary files from the file system when exporting a note to PDF. This exploit requires the attacker's ability to modify a note and affects all instances with PDF export enabled. The impact is significant, as the attacker can read the HedgeDoc
config.json file and other files on the filesystem, potentially accessing sensitive information, database credentials, and OAuth secrets.Recommendations:
For versions prior to 1.5.0, upgrade to version 1.5.0 to resolve the issue.
As a temporary workaround, consider starting the HedgeDoc instance with
CMD ALLOW PDF EXPORT=false or set "allowPDFExport": false in config.json to mitigate this issue.Fix
SSRF
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hedgedoc