TROYANOSYVIRUS
Back to CVEs

CVE-2021-32744

CRITICAL
9.8

Description

Collabora Online is a collaborative online office suite. In versions prior to 4.2.17-1 and version 6.4.9-5, unauthenticated attackers are able to gain access to files which are currently opened by other users in the Collabora Online editor. For successful exploitation the attacker is required to guess the file identifier - the predictability of this file identifier is dependent on external file-storage implementations (this is a potential "IDOR" - Insecure Direct Object Reference - vulnerability). Versions 4.2.17-1 and 6.4.9-5 contain patches for this issue. There is no known workaround except updating the Collabora Online application to one of the patched releases.

CVE Details

CVSS v3.1 Score9.8
SeverityCRITICAL
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published7/21/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

collabora:online

Weaknesses (CWE)

CWE-639CWE-639

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.