CVE-2024-30265

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2024-30265
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-30265.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-30265
Aliases
Published
2024-04-03T23:15:13Z
Modified
2024-05-14T13:10:55.413022Z
Summary
[none]
Details

Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.

References

Affected packages

Git / github.com/voila-dashboards/voila

Affected ranges

Type
GIT
Repo
https://github.com/voila-dashboards/voila
Events

Affected versions

0.*

0.0.1
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.1.0
0.1.1
0.1.10
0.1.11
0.1.12
0.1.13
0.1.14
0.1.15
0.1.16
0.1.17
0.1.18
0.1.19
0.1.2
0.1.20
0.1.21
0.1.3
0.1.4
0.1.5
0.1.6
0.1.7
0.1.8
0.1.9
0.2.0
0.2.0a0
0.2.0a1
0.2.0a2
0.2.0a3
0.2.0b0
0.2.0b1
0.2.1
0.2.10
0.2.11
0.2.12
0.2.15
0.2.2
0.2.3
0.2.4
0.2.5
0.2.6
0.2.7
0.2.8
0.2.9

@voila-dashboards/jupyterlab-preview@2.*

@voila-dashboards/jupyterlab-preview@2.0.5
@voila-dashboards/jupyterlab-preview@2.0.6
@voila-dashboards/jupyterlab-preview@2.0.7
@voila-dashboards/jupyterlab-preview@2.1.0
@voila-dashboards/jupyterlab-preview@2.1.0-alpha.0
@voila-dashboards/jupyterlab-preview@2.1.0-alpha.1
@voila-dashboards/jupyterlab-preview@2.1.0-alpha.2
@voila-dashboards/jupyterlab-preview@2.1.0-beta.0
@voila-dashboards/jupyterlab-preview@2.1.0-rc.0
@voila-dashboards/jupyterlab-preview@2.1.1
@voila-dashboards/jupyterlab-preview@2.1.2
@voila-dashboards/jupyterlab-preview@2.1.3
@voila-dashboards/jupyterlab-preview@2.1.4
@voila-dashboards/jupyterlab-preview@2.1.5
@voila-dashboards/jupyterlab-preview@2.1.6
@voila-dashboards/jupyterlab-preview@2.2.0
@voila-dashboards/jupyterlab-preview@2.2.0-alpha.0
@voila-dashboards/jupyterlab-preview@2.2.0-alpha.1
@voila-dashboards/jupyterlab-preview@2.2.0-alpha.2
@voila-dashboards/jupyterlab-preview@2.2.0-beta.0
@voila-dashboards/jupyterlab-preview@2.2.0-rc.0
@voila-dashboards/jupyterlab-preview@2.2.0-rc.1

@voila-dashboards/voila@0.*

@voila-dashboards/voila@0.2.13
@voila-dashboards/voila@0.2.14
@voila-dashboards/voila@0.2.16
@voila-dashboards/voila@0.3.0
@voila-dashboards/voila@0.3.0-alpha.0
@voila-dashboards/voila@0.3.0-alpha.1
@voila-dashboards/voila@0.3.0-alpha.2
@voila-dashboards/voila@0.3.0-beta.0
@voila-dashboards/voila@0.3.0-rc.0
@voila-dashboards/voila@0.3.1
@voila-dashboards/voila@0.3.2
@voila-dashboards/voila@0.3.3
@voila-dashboards/voila@0.3.4
@voila-dashboards/voila@0.3.5
@voila-dashboards/voila@0.3.6
@voila-dashboards/voila@0.4.0
@voila-dashboards/voila@0.4.0-alpha.0
@voila-dashboards/voila@0.4.0-alpha.1
@voila-dashboards/voila@0.4.0-alpha.2
@voila-dashboards/voila@0.4.0-beta.0
@voila-dashboards/voila@0.4.0-rc.0
@voila-dashboards/voila@0.4.0-rc.1

v0.*

v0.2.13
v0.2.14
v0.2.16
v0.3.0
v0.3.0a0
v0.3.0a1
v0.3.0a2
v0.3.0b0
v0.3.0rc0
v0.3.1
v0.3.2
v0.3.3
v0.3.4
v0.3.5
v0.3.6
v0.4.0
v0.4.0a0
v0.4.0a1
v0.4.0a2
v0.4.0b0
v0.4.0rc0
v0.4.0rc1
v0.4.1
v0.4.2
v0.4.3