CVE-2021-43817

Source
https://cve.org/CVERecord?id=CVE-2021-43817
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43817.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-43817
Related
  • GHSA-7f6h-v9mx-58q9
Published
2021-12-13T20:15:07.700Z
Modified
2026-04-10T04:41:21.328319Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Collabora Online is a collaborative online office suite based on LibreOffice technology. In affected versions a reflected XSS vulnerability was found in Collabora Online. An attacker could inject unescaped HTML into a variable as they created the Collabora Online iframe, and execute scripts inside the context of the Collabora Online iframe. This would give access to a small set of user settings stored in the browser, as well as the session's authentication token which was also passed in at iframe creation time. Users should upgrade to Collabora Online 6.4.16 or higher or Collabora Online 4.2.20 or higher. Collabora Online Development Edition 21.11 is not affected.

References

Affected packages

Git / github.com/collaboraonline/online

Affected ranges

Type
GIT
Repo
https://github.com/collaboraonline/online
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.2.20"
        }
    ]
}

Affected versions

1.*
1.6.0-0
1.6.0-4-CODE
1.6.2-1
Other
co-4-2-0-branch-point
collabora-online-1-0-branch-point
collabora-online-1-9-branch-point
collabora-online-2-0-branch-point
collabora-online-2-1-branch-point
collabora-online-3-0-branch-point
collabora-online-4-branch-point
libreoffice-5-2-branch-point
libreoffice-5-3-branch-point
libreoffice-5-4-branch-point
libreoffice-6-0-branch-point
libreoffice-6-1-branch-point
libreoffice-6-2-branch-point
libreoffice-6-3-branch-point
libreoffice-6-4-branch-point
libreoffice-7-0-branch-point
cp-4.*
cp-4.2-13-1
cp-4.2.11-1
cp-4.2.12-1
cp-4.2.12-2
cp-4.2.13-1
cp-4.2.14-1
cp-4.2.15-1
cp-4.2.16-1
cp-4.2.18-1
cp-4.2.19-1
cp-4.2.4-1
cp-4.2.4-2
cp-4.2.9-1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43817.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "6.4.0"
            },
            {
                "fixed": "6.4.16"
            }
        ]
    }
]