Information disclosure in HedgeDoc - CVE-2022-24837

 

Information disclosure in HedgeDoc - CVE-2022-24837

Published: April 10, 2022 / Updated: April 25, 2026


Vulnerability identifier: #VU127917
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-24837
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: HedgeDoc
Affected software:
HedgeDoc

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in uploaded file names when accessing uploaded images. A remote attacker can enumerate upload file names to disclose sensitive information.

This affects all upload backends except Lutim and imgur, and is especially relevant for private notes.


How to mitigate CVE-2022-24837

Install security update from vendor's website.

Sources