PT-2024-20756 · Collabora · Collabora Online
Damien Couturier
·
Published
2024-03-11
·
Updated
2024-03-12
·
CVE-2024-25114
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Collabora Online versions prior to 21.11.10
Collabora Online versions prior to 22.05.22
Collabora Online versions prior to 23.05.9
Description
Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "Kit" instance in a different "jail" with a unique directory "jailID" name. The vulnerability allows an attacker to use the CELL() function, with the "filename" argument, in the spreadsheet component to get a path which includes this JailID. The impact of this issue is low because it requires to be chained with another vulnerability.
Recommendations
For Collabora Online versions prior to 21.11.10, upgrade to version 21.11.10 or higher.
For Collabora Online versions prior to 22.05.22, upgrade to version 22.05.22 or higher.
For Collabora Online versions prior to 23.05.9, upgrade to version 23.05.9 or higher.
As a temporary workaround, consider restricting the use of the CELL() function with the
filename argument in the spreadsheet component until a patch is available.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Collabora Online