CVE-2024-30265

Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voil dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voil dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voil is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
GitHub_MCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADPADP
---
---
CVEADP
---
---