CVE-2024-5261 TLS certificates are not properly verified when utilizing LibreOfficeKit
Package
coolwsd
(Collabora Online)
Affected versions
< 24.04.3
< 23.05.12
< 22.05.23
Patched versions
24.04.3
23.05.12
22.05.23
Collabora Online internally makes use of "curl" via LibreOfficeKit to fetch remote resources such as images hosted on webservers. In affected versions of Collabora Online, in LibreOfficeKit, curl's TLS certificate verification was disabled (CURLOPT_SSL_VERIFYPEER of false). In the fixed versions curl operates in LibreOfficeKit mode the same as in standard mode with CURLOPT_SSL_VERIFYPEER of true.
References