CVE-2024-37311 Remote host TLS certificates are not fully verified
Package
coolwsd
(Collabora Online)
Affected versions
< 24.04.4.3
< 23.05.14.1
< 22.05.23.1
Patched versions
24.04.4.3
23.05.14.1
22.05.23.1
Impact
In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust
Patches
Users should upgrade to
For more information
See SSL configuration section of the Configuration guide if upgrading triggers invalid certificate warnings
If you have any questions or comments about this advisory: