PT-2021-19900 · Collabora · Collabora Online
Lukas Reschke
·
Published
2021-07-21
·
Updated
2021-07-30
·
CVE-2021-32744
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Collabora Online versions prior to 4.2.17-1
Collabora Online version 6.4.9-5
Description
Collabora Online is a collaborative online office suite. Unauthenticated attackers can gain access to files currently opened by other users in the Collabora Online editor. The attacker must guess the file identifier, which is dependent on external file-storage implementations. This is a potential Insecure Direct Object Reference vulnerability.
Recommendations
For versions prior to 4.2.17-1, update to version 4.2.17-1 or later.
For version 6.4.9-5, update to a patched release.
At the moment, there is no information about other newer versions that contain a fix for this vulnerability.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Collabora Online