CVE-2022-31024: Federated editing allows iframing remote servers by default in richdocuments
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and 4.2.6 contain a fix for this issue. There are currently no known workarounds available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-31024.
What is the severity of CVE-2022-31024?
The severity of CVE-2022-31024 is medium, with a severity value of 6.5.
What is affected by CVE-2022-31024?
The Nextcloud Richdocuments app versions up to 4.2.6, 5.0.0 to 5.0.4, and 6.0.0-beta1 are affected by CVE-2022-31024.
How can a user be exploited by CVE-2022-31024?
A user can be tricked into working against a remote Office by sending them a federated share.
Where can I find more information about CVE-2022-31024?
You can find more information about CVE-2022-31024 on GitHub (https://github.com/nextcloud/richdocuments/pull/2161) and HackerOne (https://hackerone.com/reports/1210424).