THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-30265

Voilà Local file inclusion

AssignerGitHub_M
Reserved2024-03-26
Published2024-04-03
Updated2024-06-04

Description

Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.



HIGH: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-73: External Control of File Name or Path

Product status

>= 0.0.2, < 0.2.17
affected

>= 0.3.0a0, < 0.3.8
affected

>= 0.4.0a0, < 0.4.4
affected

>= 0.5.0a0, < 0.5.6
affected

References

https://github.com/voila-dashboards/voila/security/advisories/GHSA-2q59-h24c-w6fg

https://github.com/voila-dashboards/voila/commit/00d6362c237b6b4d466873535554d6076ead0c52

https://github.com/voila-dashboards/voila/commit/28faacc9b03b160fd8fa920ad045f4ec0667ab67

https://github.com/voila-dashboards/voila/commit/5542e4ae36bb5d184deaa48f95e76be477756af2

https://github.com/voila-dashboards/voila/commit/98b6a40fec27723572314fdbba99bdc147d904c8

https://github.com/voila-dashboards/voila/commit/c045be6988539d07cceeb9f82fc660a49485d504

cve.org CVE-2024-30265

nvd.nist.gov CVE-2024-30265

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-30265
© Copyright 2024 THREATINT. Made in Cyprus with +