CVE-2021-29474 describes a path traversal vulnerability in HedgeDoc (formerly CodiMD), an open-source collaborative markdown editor. Improper input validation allows an unauthenticated attacker to read arbitrary .md files from the server's filesystem. The CVSS score of 5.8 (Medium) indicates a network-based attack with low complexity, requiring no user interaction, and resulting in low confidentiality impact. While the attack's usefulness is limited to .md files and often public content, it can reveal changes to these files. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.0CPE matchmatch criteria | cpe:2.3:a:hedgedoc:hedgedoc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.