Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Jimmywarting

#50361of 56,335
5.3Total CVSS
Vulnerabilities · 1
PT-2022-16912
5.3
2022-04-11
Hedgedoc · Hedgedoc · CVE-2022-24837
**Name of the Vulnerable Software and Affected Versions** HedgeDoc versions 1.9.1 through 1.9.2 **Description** HedgeDoc is an open-source, web-based, self-hosted, collaborative markdown editor. Images uploaded with HedgeDoc have an enumerable filename after the upload, resulting in potential information leakage of uploaded documents. This is especially relevant for private notes and affects all upload backends, except Lutim and imgur. **Recommendations** For HedgeDoc versions 1.9.1 and 1.9.2, upgrade to version 1.9.3 to patch the issue by replacing the filename generation with UUIDv4. As a temporary workaround for versions 1.9.1 and 1.9.2, consider blocking POST requests to "/uploadimage" to disable future uploads.