Skip to main content

External Control of File Name or Path

CVE-2024-30265

Severity High
Score 7.5/10

Summary

Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voila dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voila dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voila is deployed. The issues affect versions 0.0.2 through 0.2.16, 0.3.0a0 through 0.3.7, 0.4.0a0 through 0.4.3, and 0.5.0a0 through 0.5.5.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • NONE

CWE-73 - External Control of File Name or Path

The software allows user input to control or influence paths or file names that are used in filesystem operations.

Advisory Timeline

  • Published