漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Collabora Online Vulnerable to Arbitrary File Write
Vulnerability Description
Collabora Online is a collaborative online office suite based on LibreOffice technology. In versions prior to 24.04.12.4, 23.05.19, and 22.05.25, there is a path traversal flaw in handling the CheckFileInfo BaseFileName field returned from WOPI servers. This allows for a file to be written anywhere the uid running Collabora Online can write, if such a response was supplied by a malicious WOPI server. By combining this flaw with a Time of Check, Time of Use DNS lookup issue with a WOPI server address under attacker control, it is possible to present such a response to be processed by a Collabora Online instance. This issue has been patched in versions 24.04.13.1, 23.05.19, and 22.05.25.
CVSS Information
N/A
Vulnerability Type
相对路径遍历
Vulnerability Title
Collabora Online 安全漏洞
Vulnerability Description
Collabora Online是英国Collabora公司的一个应用软件。一个强大的基于 LibreOffice 的在线办公室,支持所有主要的文档、电子表格和演示文件格式。 Collabora Online 24.04.12.4之前版本、23.05.19版本和22.05.25版本存在安全漏洞,该漏洞源于处理WOPI服务器返回的CheckFileInfo BaseFileName字段时存在路径遍历缺陷,可能导致任意文件写入。
CVSS Information
N/A
Vulnerability Type
N/A