Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. This vulnerability is fixed in Collabora Online 24.04.4.3, 23.05.14.1, and 22.05.23.1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-295"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37311.json"
}{
"extracted_events": [
{
"introduced": "24.04.1.1"
},
{
"fixed": "24.04.4.3"
},
{
"introduced": "23.05.0-1"
},
{
"fixed": "23.05.14-1"
},
{
"introduced": "0"
},
{
"fixed": "22.05.23.1"
}
],
"source": "AFFECTED_FIELD"
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37311.json"
[
{
"target": {
"file": "wsd/Storage.cpp"
},
"deprecated": false,
"source": "https://github.com/collaboraonline/online/commit/bad165851667c08ae4547374e21865c3b4f1c13a",
"id": "CVE-2024-37311-10824b1c",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"33240060825508422689783061356871092526",
"37959778313031036346544832990338660119",
"194945003374552761539087258057538349728",
"177844959191370068911328113256191313685",
"53295121197594261101159513564108881488",
"163111359089526212073669911205296093059",
"29184145815082986339269343933654085973",
"222668626704185494525625406207664523479",
"13771912527967999841991046855837340111",
"1298497036757060208446457744914365159",
"176545128759654935332910989202135941352",
"265231290620897161009783627730488594426",
"35905336109803927238107985410464144747",
"155789988923961308486814915628838841190",
"142247747007989922670082820230833607807"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "wsd/Storage.cpp"
},
"deprecated": false,
"source": "https://github.com/collaboraonline/online/commit/54a2d4264429d972e4205ec05b36e00e1303cb09",
"id": "CVE-2024-37311-140c1733",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"33240060825508422689783061356871092526",
"37959778313031036346544832990338660119",
"194945003374552761539087258057538349728",
"177844959191370068911328113256191313685",
"53295121197594261101159513564108881488",
"163111359089526212073669911205296093059",
"29184145815082986339269343933654085973",
"222668626704185494525625406207664523479",
"13771912527967999841991046855837340111",
"1298497036757060208446457744914365159",
"176545128759654935332910989202135941352",
"265231290620897161009783627730488594426",
"35905336109803927238107985410464144747",
"155789988923961308486814915628838841190",
"142247747007989922670082820230833607807"
]
},
"signature_type": "Line"
},
{
"target": {
"function": "StorageBase::initialize",
"file": "wsd/Storage.cpp"
},
"deprecated": false,
"source": "https://github.com/collaboraonline/online/commit/bad165851667c08ae4547374e21865c3b4f1c13a",
"id": "CVE-2024-37311-393b6f57",
"signature_version": "v1",
"digest": {
"length": 3097.0,
"function_hash": "59102960834504974511515326281074103258"
},
"signature_type": "Function"
},
{
"target": {
"function": "StorageBase::initialize",
"file": "wsd/Storage.cpp"
},
"deprecated": false,
"source": "https://github.com/collaboraonline/online/commit/54a2d4264429d972e4205ec05b36e00e1303cb09",
"id": "CVE-2024-37311-ae19afc3",
"signature_version": "v1",
"digest": {
"length": 3097.0,
"function_hash": "59102960834504974511515326281074103258"
},
"signature_type": "Function"
}
]
"2026-08-12T15:15:18Z"