Information disclosure in HedgeDoc - CVE-2022-24837
Published: April 10, 2022 / Updated: April 25, 2026
HedgeDoc
HedgeDoc
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information in uploaded file names when accessing uploaded images. A remote attacker can enumerate upload file names to disclose sensitive information.
This affects all upload backends except Lutim and imgur, and is especially relevant for private notes.