CVE-2024-30265
Last modified
CVE-2024-30265 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-30265?
How severe is CVE-2024-30265?
How do I fix CVE-2024-30265?
Are you affected by CVE-2024-30265?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
