Skip to content

CVE-2023-49788 Improper handling of browser-side provided input in richdocuments path handling

High
caolanm published GHSA-3r69-xvf7-v94j Dec 8, 2023

Package

richdocumentscode (richdocumentscode)

Affected versions

< 23.5.602

Patched versions

23.5.602

Description

Impact

Unlike a standalone dedicated Collabora Online server, the Built-in CODE Server (richdocumentscode) is run without chroot sandboxing. Vulnerable versions of the richdocumentscode app can be susceptible to attack via modified client->server commands to overwrite files outside the sub directory the server has provided for the transient session.

Patches

The bug was fixed in Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.602.

Workarounds

None, except removing Collabora Online - Built-in CODE Server (richdocumentscode) app or using standalone dedicated Collabora Online server.

Credits

Thanks to Reginaldo Silva of ubercomp.com for discovering this flaw.

Severity

High

CVE ID

CVE-2023-49788

Weaknesses

Credits