Related Vulnerabilities: CVE-2021-29474  

A security issue has been found in HedgeDoc before version 1.8.0. An attacker can read arbitrary .md files from the server's filesystem due to an improper input validation, which results in the ability to perform a relative path traversal.

Severity Medium

Remote Yes

Type Information disclosure

Description

A security issue has been found in HedgeDoc before version 1.8.0. An attacker can read arbitrary .md files from the server's filesystem due to an improper input validation, which results in the ability to perform a relative path traversal.

AVG-1876 hedgedoc 1.7.2-2 Medium Vulnerable

https://github.com/hedgedoc/hedgedoc/security/advisories/GHSA-p528-555r-pf87