SB2018040702 - Multiple vulnerabilities in Etherpad
Published: April 7, 2018 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Information disclosure (CVE-ID: CVE-2018-9325)
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.
2) Input validation error (CVE-ID: CVE-2018-9327)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).
Remediation
Install update from vendor's website.