CVE-2024-37311

Aug. 23, 2024, 4:18 p.m.

Awaiting Analysis
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Collabora Online

  • 24.04.4.3
  • 23.05.14.1
  • 22.05.23.1

Source

security-advisories@github.com

Tags

CVE-2024-37311 details

Published : Aug. 23, 2024, 3:15 p.m.
Last Modified : Aug. 23, 2024, 4:18 p.m.

Description

Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. This vulnerability is fixed in Collabora Online 24.04.4.3, 23.05.14.1, and 22.05.23.1.

CVSS Score

1 2 3 4 5 6 7 8.2 9 10

Weakness

Weakness Name Description
CWE-295 Improper Certificate Validation The product does not validate, or incorrectly validates, a certificate.

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

LOW

Availability Impact

NONE

Base Score

8.2

Exploitability Score

3.9

Impact Score

4.2

Base Severity

HIGH

References

URL Source
https://github.com/CollaboraOnline/online/security/advisories/GHSA-hvhm-5c44-977x security-advisories@github.com
This website uses the NVD API, but is not approved or certified by it.