Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1068 | Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6. |
Github GHSA |
GHSA-2q59-h24c-w6fg | Voilà Local file inclusion |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T01:32:06.621Z
Reserved: 2024-03-26T12:52:00.935Z
Link: CVE-2024-30265
Updated: 2024-08-02T01:32:06.621Z
Status : Awaiting Analysis
Published: 2024-04-03T23:15:13.423
Modified: 2024-11-21T09:11:35.073
Link: CVE-2024-30265
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA