PT-2024-20756 · Collabora · Collabora Online

Damien Couturier

·

Published

2024-03-11

·

Updated

2024-03-12

·

CVE-2024-25114

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Collabora Online versions prior to 21.11.10 Collabora Online versions prior to 22.05.22 Collabora Online versions prior to 23.05.9
Description Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "Kit" instance in a different "jail" with a unique directory "jailID" name. The vulnerability allows an attacker to use the CELL() function, with the "filename" argument, in the spreadsheet component to get a path which includes this JailID. The impact of this issue is low because it requires to be chained with another vulnerability.
Recommendations For Collabora Online versions prior to 21.11.10, upgrade to version 21.11.10 or higher. For Collabora Online versions prior to 22.05.22, upgrade to version 22.05.22 or higher. For Collabora Online versions prior to 23.05.9, upgrade to version 23.05.9 or higher. As a temporary workaround, consider restricting the use of the CELL() function with the filename argument in the spreadsheet component until a patch is available.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-25114
GHSA-2FH2-PPJF-P3XV

Affected Products

Collabora Online