Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. This vulnerability is fixed in Collabora Online 24.04.4.3, 23.05.14.1, and 22.05.23.1.
History

Fri, 23 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
Description Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. This vulnerability is fixed in Collabora Online 24.04.4.3, 23.05.14.1, and 22.05.23.1.
Title Collabora Online's remote host TLS certificates are not fully verified
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-23T14:26:45.894Z

Updated: 2024-08-23T16:12:01.820Z

Reserved: 2024-06-05T20:10:46.498Z

Link: CVE-2024-37311

cve-icon Vulnrichment

Updated: 2024-08-23T16:11:56.302Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-23T15:15:15.617

Modified: 2024-08-23T16:18:28.547

Link: CVE-2024-37311

cve-icon Redhat

No data.