CVE-2024-45313 affects Overleaf Server Pro installations using older Toolkit or docker-compose configurations, where insecure default settings for LaTeX compiles allowed users access to container resources. This vulnerability, rated Medium (CVSS 5.4), permits unauthorized file access (CWE-1188, CWE-284) due to misconfigured security features. While there is no evidence of active exploitation, exploit code, or significant community discussion, administrators are advised to enable SIBLING_CONTAINERS_ENABLED or SANDBOXED_COMPILES for mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2024-07-17CPE matchmatch criteria | cpe:2.3:a:overleaf:overleaf:*:*:*:*:server_pro:*:*:* | ||
< 2024-08-28CPE matchmatch criteria | cpe:2.3:a:overleaf:overleaf:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.