SB2022041016 - Information disclosure in HedgeDoc



SB2022041016 - Information disclosure in HedgeDoc

Published: April 10, 2022 Updated: April 25, 2026

Security Bulletin ID SB2022041016
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2022-24837)

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in uploaded file names when accessing uploaded images. A remote attacker can enumerate upload file names to disclose sensitive information.

This affects all upload backends except Lutim and imgur, and is especially relevant for private notes.


Remediation

Install update from vendor's website.