Voilà Local file inclusion
Vulnerability Description
Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-30265
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/voila-dashboards/voila/security/advisories/GHSA-2q59-h24c-w6fg
- https://github.com/voila-dashboards/voila/commit/00d6362c237b6b4d466873535554d6076ead0c52
- https://github.com/voila-dashboards/voila/commit/28faacc9b03b160fd8fa920ad045f4ec0667ab67
- https://github.com/voila-dashboards/voila/commit/5542e4ae36bb5d184deaa48f95e76be477756af2
- https://github.com/voila-dashboards/voila/commit/98b6a40fec27723572314fdbba99bdc147d904c8
- https://github.com/voila-dashboards/voila/commit/c045be6988539d07cceeb9f82fc660a49485d504
Affected Vendor
voila-dashboards
View all reports →