{"id":"CVE-2024-37311","summary":"Collabora Online's remote host TLS certificates are not fully verified","details":"Collabora Online is a collaborative online office suite based on LibreOffice. In affected versions of Collabora Online, https connections from coolwsd to other hosts may incompletely verify the remote host's certificate's against the full chain of trust. This vulnerability is fixed in Collabora Online 24.04.4.3, 23.05.14.1, and 22.05.23.1.","aliases":["GHSA-hvhm-5c44-977x"],"modified":"2026-07-22T03:35:12.857724Z","published":"2024-08-23T14:26:45.894Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37311.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-295"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37311.json"},{"type":"ADVISORY","url":"https://github.com/CollaboraOnline/online/security/advisories/GHSA-hvhm-5c44-977x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37311"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/collaboraonline/online","events":[{"introduced":"39ee21ddca6daf5b6d66a8e99d15443e45a9b0cc"},{"fixed":"8628721243bf59b9659e7901b708ef60ee87f4be"},{"introduced":"012b00d6d4530fb7e74fac5c32696c82de028036"},{"fixed":"54a2d4264429d972e4205ec05b36e00e1303cb09"},{"introduced":"0"},{"fixed":"bad165851667c08ae4547374e21865c3b4f1c13a"}],"database_specific":{"extracted_events":[{"introduced":"24.04.1.1"},{"fixed":"24.04.4.3"},{"introduced":"23.05.0-1"},{"fixed":"23.05.14-1"},{"introduced":"0"},{"fixed":"22.05.23.1"}],"source":"AFFECTED_FIELD"}}],"versions":["cp-24.04.4-2","helm-collabora-online-1.1.17","cp-23.05.13-1","cp-24.04.4-1","cp-23.05.12-1","helm-collabora-online-1.1.16","cp-24.04.3-1","cp-24.04.2-1","cp-23.05.11-1","cp-24.04.1-3","helm-collabora-online-1.1.15","cp-24.04.1-2","cp-23.05.10-1","cp-24.04.1-1","cp-23.05.9-4","cp-23.05.9-3","cp-22.05.22-2","cp-23.05.9-2","cp-22.05.22-1","cp-23.05.9-1","cp-23.05.8-4","cp-23.05.8-3","cp-23.05.8-2","cp-23.05.8-1","cp-23.05.7-5","cp-23.05.7-4","cp-23.05.7-3","cp-23.05.7-2","cp-22.05.21-1","cp-23.05.7-1","helm-collabora-online-1.1.9","helm-collabora-online-1.1.8","helm-collabora-online-1.1.7","helm-collabora-online-1.1.6","helm-collabora-online-1.1.5","cp-22.05.20-1","helm-collabora-online-1.1.4","cp-23.05.5-2","helm-collabora-online-1.1.3","cp-23.05.5-1","co-23.05-branch-point","cp-22.05.19-1","cp-23.05.4-2","cp-23.05.4-1","cp-22.05.18-1","cp-23.05.3-1","helm-collabora-online-1.1.2","cp-22.05.17-1","helm-collabora-online-1.1.1","cp-23.05.2-2","cp-23.05.2-1","helm-collabora-online-1.1.0","helm-collabora-online-1.0.2","helm-collabora-online-1.0.1","cp-22.05.16-1","cp-23.05.1-1","cp-23.05.0-5","cp-23.05.0-4","cp-23.05.0-3","cp-23.05.0-2","cp-22.05.15-2","cp-22.05.15-1","cp-23.05.0-1","cp-22.05.14-3","cp-22.05.14-2","cp-22.05.14-1","cp-22.05.12-4","cp-22.05.12-3","cp-22.05.12-2","cp-22.05.12-1","cp-22.05.11-1","cp-22.05.10-7","cp-22.05.10-6","cp-22.05.10-2","cp-22.05.9-6","cp-22.05.9-5","cp-22.05.9-4","cp-22.05.9-3","cp-22.05.8-4","cp-22.05.8-3","cp-22.05.7-5","cp-22.05.7-4","cp-22.05.7-3","cp-22.05.6-3","cp-22.05.6-2","cp-22.05.5-3","cp-22.05.5-2","cp-22.05.5-1","cp-22.05.4-1","cp-22.05.3-1","cp-22.05.0-1","cp-21.11.3-0","cp-21.11.0-6","cp-21.11.0-5","cp-21.11.0-4","cp-21.11.0-3","cp-21.11.0-2","cp-21.11.0-1","cp-21.11.0-0","cp-21.06.2-0","for-code-assets","libreoffice-7-0-branch-point","co-4-2-0-branch-point","libreoffice-6-4-branch-point","libreoffice-6-3-branch-point","collabora-online-4-branch-point","libreoffice-6-2-branch-point","libreoffice-6-1-branch-point","libreoffice-6-0-branch-point","collabora-online-3-0-branch-point","libreoffice-5-4-branch-point","collabora-online-2-1-branch-point","collabora-online-2-0-branch-point","libreoffice-5-3-branch-point","collabora-online-1-9-branch-point","libreoffice-5-2-branch-point","collabora-online-1-0-branch-point","1.6.2-1","1.6.0-4-CODE","1.6.0-0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-37311.json","vanir_signatures_modified":"2026-07-22T03:35:12Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["33240060825508422689783061356871092526","37959778313031036346544832990338660119","194945003374552761539087258057538349728","177844959191370068911328113256191313685","53295121197594261101159513564108881488","163111359089526212073669911205296093059","29184145815082986339269343933654085973","222668626704185494525625406207664523479","13771912527967999841991046855837340111","1298497036757060208446457744914365159","176545128759654935332910989202135941352","265231290620897161009783627730488594426","35905336109803927238107985410464144747","155789988923961308486814915628838841190","142247747007989922670082820230833607807"],"threshold":0.9},"id":"CVE-2024-37311-10824b1c","signature_type":"Line","signature_version":"v1","source":"https://github.com/collaboraonline/online/commit/bad165851667c08ae4547374e21865c3b4f1c13a","target":{"file":"wsd/Storage.cpp"}},{"id":"CVE-2024-37311-140c1733","signature_type":"Line","signature_version":"v1","source":"https://github.com/collaboraonline/online/commit/54a2d4264429d972e4205ec05b36e00e1303cb09","target":{"file":"wsd/Storage.cpp"},"deprecated":false,"digest":{"line_hashes":["33240060825508422689783061356871092526","37959778313031036346544832990338660119","194945003374552761539087258057538349728","177844959191370068911328113256191313685","53295121197594261101159513564108881488","163111359089526212073669911205296093059","29184145815082986339269343933654085973","222668626704185494525625406207664523479","13771912527967999841991046855837340111","1298497036757060208446457744914365159","176545128759654935332910989202135941352","265231290620897161009783627730488594426","35905336109803927238107985410464144747","155789988923961308486814915628838841190","142247747007989922670082820230833607807"],"threshold":0.9}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/collaboraonline/online/commit/bad165851667c08ae4547374e21865c3b4f1c13a","target":{"file":"wsd/Storage.cpp","function":"StorageBase::initialize"},"deprecated":false,"digest":{"function_hash":"59102960834504974511515326281074103258","length":3097},"id":"CVE-2024-37311-393b6f57"},{"id":"CVE-2024-37311-ae19afc3","signature_type":"Function","signature_version":"v1","source":"https://github.com/collaboraonline/online/commit/54a2d4264429d972e4205ec05b36e00e1303cb09","target":{"file":"wsd/Storage.cpp","function":"StorageBase::initialize"},"deprecated":false,"digest":{"function_hash":"59102960834504974511515326281074103258","length":3097}}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N"}]}