SB2022041016 - Information disclosure in HedgeDoc
Published: April 10, 2022 Updated: April 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2022-24837)
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in uploaded file names when accessing uploaded images. A remote attacker can enumerate upload file names to disclose sensitive information.
This affects all upload backends except Lutim and imgur, and is especially relevant for private notes.
Remediation
Install update from vendor's website.