First published: Fri Dec 08 2023(Updated: )
Collabora Online is a collaborative online office suite based on LibreOffice technology. Users of Nextcloud with `Collabora Online - Built-in CODE Server` app can be vulnerable to attack via proxy.php. The bug was fixed in Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.601. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Collabora Office | <23.5.601 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49782 is categorized as a moderate severity vulnerability affecting the Collabora Online - Built-in CODE Server.
To fix CVE-2023-49782, you should update the Collabora Online - Built-in CODE Server app to version 23.5.601 or later.
CVE-2023-49782 affects users of Nextcloud using the Collabora Online - Built-in CODE Server app prior to version 23.5.601.
Exploiting CVE-2023-49782 could potentially allow an attacker to compromise user data through the proxy.php file.
As of now, there are no publicly known exploits for CVE-2023-49782, but users are advised to update their systems to mitigate any potential risks.