We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Users of Nextcloud with Collabora Online - Built-in CODE Server app can be vulnerable to attack via proxy.php.
The bug was fixed in Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.601.
None, except removing Collabora Online - Built-in CODE Server (richdocumentscode) app or using standalone dedicated Collabora Online server.
Thanks to @Ry0taK for discovering and reporting this vulnerability
Impact
Users of Nextcloud with Collabora Online - Built-in CODE Server app can be vulnerable to attack via proxy.php.
Patches
The bug was fixed in Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.601.
Workarounds
None, except removing Collabora Online - Built-in CODE Server (richdocumentscode) app or using standalone dedicated Collabora Online server.
Credits
Thanks to @Ry0taK for discovering and reporting this vulnerability