Skip to content

CVE-2023-48314 Unescaped passing of the request URL

High
timar published GHSA-qjrm-q4h5-v3r2 Nov 27, 2023

Package

No package listed

Affected versions

<23.5.403

Patched versions

23.5.403

Description

Impact

Users of Nextcloud with Collabora Online - Built-in CODE Server app can be vulnerable to attack via proxy.php.

Patches

The bug was fixed in Collabora Online - Built-in CODE Server (richdocumentscode) release 23.5.403.

Workarounds

None, except removing Collabora Online - Built-in CODE Server (richdocumentscode) app.

Severity

High

CVE ID

CVE-2023-48314

Weaknesses

No CWEs