Security vulnerability in OpenOlat's Draw.io integration allows for arbitrary file reading
CVE-2024-28198
7.5HIGH
What is CVE-2024-28198?
The OpenOlat e-learning platform has a security flaw allowing unauthorized reading of arbitrary files due to improper handling of HTTP requests during the use of the draw.io integration. A successful exploitation can lead to sensitive data exposure as the system user. Users are encouraged to upgrade to version 18.1.6 or 18.2.2 to mitigate this risk. Alternatively, disabling the Draw.io module or the entire REST API can serve as a temporary workaround to secure the system until an upgrade can be performed.
Affected Version(s)
OpenOLAT < 18.1.6
