PT-2022-16912 · Hedgedoc · Hedgedoc

Jimmywarting

·

Published

2022-04-11

·

Updated

2022-04-19

·

CVE-2022-24837

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions HedgeDoc versions 1.9.1 through 1.9.2
Description HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc have an enumerable filename after the upload, resulting in potential information leakage of uploaded documents. This is especially relevant for private notes and affects all upload backends, except Lutim and imgur.
Recommendations For HedgeDoc versions 1.9.1 and 1.9.2, upgrade to version 1.9.3 to patch the issue by replacing the filename generation with UUIDv4. As a temporary workaround for versions 1.9.1 and 1.9.2, consider blocking POST requests to "/uploadimage" to disable future uploads.

Exploit

Fix

Information Disclosure

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24837
GHSA-Q6VV-2Q26-J7RX

Affected Products

Hedgedoc