CVE-2024-30265
Estado: AplazadaAlta (7.5)—
Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.73%
- Percentil entre todas las CVEs puntuadas: 53
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-73
Referencias
- https://github.com/voila-dashboards/voila/commit/00d6362c237b6b4d466873535554d6076ead0c52
- https://github.com/voila-dashboards/voila/commit/28faacc9b03b160fd8fa920ad045f4ec0667ab67
- https://github.com/voila-dashboards/voila/commit/5542e4ae36bb5d184deaa48f95e76be477756af2
- https://github.com/voila-dashboards/voila/commit/98b6a40fec27723572314fdbba99bdc147d904c8
- https://github.com/voila-dashboards/voila/commit/c045be6988539d07cceeb9f82fc660a49485d504
- https://github.com/voila-dashboards/voila/security/advisories/GHSA-2q59-h24c-w6fg
- https://github.com/voila-dashboards/voila/commit/00d6362c237b6b4d466873535554d6076ead0c52
- https://github.com/voila-dashboards/voila/commit/28faacc9b03b160fd8fa920ad045f4ec0667ab67
- https://github.com/voila-dashboards/voila/commit/5542e4ae36bb5d184deaa48f95e76be477756af2
- https://github.com/voila-dashboards/voila/commit/98b6a40fec27723572314fdbba99bdc147d904c8
- https://github.com/voila-dashboards/voila/commit/c045be6988539d07cceeb9f82fc660a49485d504
- https://github.com/voila-dashboards/voila/security/advisories/GHSA-2q59-h24c-w6fg
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-30265",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-30265",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-04-04T16:07:37.511255Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "voila-dashboards",
"product": "voila",
"versions": [
{
"status": "affected",
"version": ">= 0.0.2, < 0.2.17"
},
{
"status": "affected",
"version": ">= 0.3.0a0, < 0.3.8"
},
{
"status": "affected",
"version": ">= 0.4.0a0, < 0.4.4"
},
{
"status": "affected",
"version": ">= 0.5.0a0, < 0.5.6"
}
]
}
]
}
],
"published": "2024-04-03T23:15:13.423",
"references": [
{
"url": "https://github.com/voila-dashboards/voila/commit/00d6362c237b6b4d466873535554d6076ead0c52",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/28faacc9b03b160fd8fa920ad045f4ec0667ab67",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/5542e4ae36bb5d184deaa48f95e76be477756af2",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/98b6a40fec27723572314fdbba99bdc147d904c8",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/c045be6988539d07cceeb9f82fc660a49485d504",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/voila-dashboards/voila/security/advisories/GHSA-2q59-h24c-w6fg",
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/00d6362c237b6b4d466873535554d6076ead0c52",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/28faacc9b03b160fd8fa920ad045f4ec0667ab67",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/5542e4ae36bb5d184deaa48f95e76be477756af2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/98b6a40fec27723572314fdbba99bdc147d904c8",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/voila-dashboards/voila/commit/c045be6988539d07cceeb9f82fc660a49485d504",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/voila-dashboards/voila/security/advisories/GHSA-2q59-h24c-w6fg",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-73"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Collabora Online is a collaborative online office suite based on LibreOffice technology. Any deployment of voilà dashboard allow local file inclusion. Any file on a filesystem that is readable by the user that runs the voilà dashboard server can be downloaded by someone with network access to the server. Whether this still requires authentication depends on how voilà is deployed. This issue has been patched in 0.2.17, 0.3.8, 0.4.4 and 0.5.6.\n"
},
{
"lang": "es",
"value": "Collabora Online es una suite ofimática colaborativa en línea basada en la tecnología LibreOffice. Cualquier implementación del panel voilà permite la inclusión de archivos locales. Cualquier archivo en un sistema de archivos que sea legible por el usuario que ejecuta el servidor del panel voilà puede ser descargado por alguien con acceso de red al servidor. Si esto todavía requiere autenticación depende de cómo se implemente voilà. Este problema se solucionó en 0.2.17, 0.3.8, 0.4.4 y 0.5.6."
}
],
"lastModified": "2026-06-17T07:26:38.180",
"sourceIdentifier": "security-advisories@github.com"
}