CVE-2024-25114 - CVE House
Back to Database
Status published Low CVE-2024-25114

Sensitive Information Disclosure (JailID) to users in Collabora Online

Vulnerability Description

Collabora Online is a collaborative online office suite based on LibreOffice technology. Each document in Collabora Online is opened by a separate "Kit" instance in a different "jail" with a unique directory "jailID" name. For security reasons, this directory name is randomly generated and should not be given out to the client. In affected versions of Collabora Online it is possible to use the CELL() function, with the "filename" argument, in the spreadsheet component to get a path which includes this JailID. The impact of this vulnerability in its own is low because it requires to be chained with another vulnerability. Users should upgrade to Collabora Online 23.05.9; Collabora Online 22.05.22; Collabora Online 21.11.10 or higher. There are no known workarounds for this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-25114

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

CollaboraOnline

View all reports →

Affected Software

online
Vulnerable Versions:
>= 23.0.0, < 23.05.9, >= 22.0.0, < 22.05.22, < 21.11.9.4

Timeline

Official Publish: March 11th, 2024
Last Modified: April 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)