LibreOffice-based Online Office Suite Vulnerability
CVE-2024-37311

8.2HIGH

Key Information:

Status
Vendor
CVE Published:
23 August 2024

Summary

Collabora Online, a collaborative online office suite built on LibreOffice, contains a vulnerability in certain versions that can result in inadequate verification of remote hosts' certificates during HTTPS connections. This flaw poses risks as it may compromise the integrity of the secure communication, potentially allowing unauthorized access or man-in-the-middle attacks. Users are encouraged to update to patched versions—Collabora Online 24.04.4.3, 23.05.14.1, or 22.05.23.1—to ensure robust security measures are in place and maintain trust in the application's functionality.

Affected Version(s)

online >= 24.04.1.1, < 24.04.4.3 < 24.04.1.1, 24.04.4.3

online >= 23.05.0-1, < 23.05.14-1 < 23.05.0-1, 23.05.14-1

online < 22.05.23.1 < 22.05.23.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.