Skip to content

CVE-2024-37311 Remote host TLS certificates are not fully verified

High
caolanm published GHSA-hvhm-5c44-977x Aug 23, 2024

Package

coolwsd (Collabora Online)

Affected versions

< 24.04.4.3
< 23.05.14.1
< 22.05.23.1

Patched versions

24.04.4.3
23.05.14.1
22.05.23.1

Description

Impact

In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust

Patches

Users should upgrade to

  • Collabora Online 24.04.4.3 or higher;
  • Collabora Online 23.05.14.1 or higher;
  • Collabora Online 22.05.23.1 or higher;

For more information

See SSL configuration section of the Configuration guide if upgrading triggers invalid certificate warnings

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2024-37311

Weaknesses