PT-2022-16912 · Hedgedoc · Hedgedoc
Jimmywarting
·
Published
2022-04-11
·
Updated
2022-04-19
·
CVE-2022-24837
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
HedgeDoc versions 1.9.1 through 1.9.2
Description
HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc have an enumerable filename after the upload, resulting in potential information leakage of uploaded documents. This is especially relevant for private notes and affects all upload backends, except Lutim and imgur.
Recommendations
For HedgeDoc versions 1.9.1 and 1.9.2, upgrade to version 1.9.3 to patch the issue by replacing the filename generation with UUIDv4.
As a temporary workaround for versions 1.9.1 and 1.9.2, consider blocking POST requests to "/uploadimage" to disable future uploads.
Exploit
Fix
Information Disclosure
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hedgedoc