SB2018040702 - Multiple vulnerabilities in Etherpad 



SB2018040702 - Multiple vulnerabilities in Etherpad

Published: April 7, 2018 Updated: July 17, 2020

Security Bulletin ID SB2018040702
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Medium 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Information disclosure (CVE-ID: CVE-2018-9325)

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to export all the existing pads of an instance without knowledge of pad names.


2) Input validation error (CVE-ID: CVE-2018-9327)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Etherpad 1.5.x and 1.6.x before 1.6.4 allows an attacker to execute arbitrary code on the server. The instance has to be configured to use a document database (DirtyDB, CouchDB, MongoDB, or RethinkDB).


Remediation

Install update from vendor's website.