CVE-2023-49788
CVSS 3.1 Score 7.2 of 10 (high)
Details
Summary
CVE-2023-49788 affects Collabora Online, an office suite based on LibreOffice technology. Unlike a dedicated server, the Built-in CODE Server (richdocumentscode) runs without chroot sandboxing, leaving it vulnerable to file overwrite attacks. Attackers can exploit this vulnerability by sending modified client-to-server commands, allowing them to overwrite files outside the session subdirectory. The server process's access permissions determine which files are at risk. Users are advised to upgrade to Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.602 to mitigate the issue, as no known workarounds have been identified.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.