Information disclosure in HedgeDoc - CVE-2022-24837

 

Information disclosure in HedgeDoc - CVE-2022-24837

Published: April 10, 2022 / Updated: April 25, 2026


Vulnerability identifier: #VU127917
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-24837
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
HedgeDoc
Software vendor:
HedgeDoc

Description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information in uploaded file names when accessing uploaded images. A remote attacker can enumerate upload file names to disclose sensitive information.

This affects all upload backends except Lutim and imgur, and is especially relevant for private notes.


Remediation

Install security update from vendor's website.

External links