Executive brief
unoconv is a command-line tool for converting documents between formats using LibreOffice. Versions before 0.9 mishandle file paths, allowing attackers to read arbitrary files from the server or access internal network resources, potentially exposing sensitive data or enabling reconnaissance of backend systems.
Technical details
unoconv before version 0.9 contains a Server-Side Request Forgery (SSRF) vulnerability caused by improper handling of untrusted pathnames. The flaw stems from the application's failure to sanitize file paths passed as input, particularly in the document update and conversion logic. An attacker can supply specially crafted file paths—including URLs or traversal sequences—that are processed by the underlying LibreOffice instance, leading to access of arbitrary local files or outbound requests to internal network resources. No authentication is required; the vulnerability is exploitable over the network through any interface that accepts file path input. The fix was addressed in version 0.9.0 by changing the default updateDocMode behavior and adding controls over link updating.
Affected products
- unoconv unoconv before 0.9.0
Timeline
- 2019-10-24: disclosed
- 2019-09-17: patched: Fix merged in PR #510, released in version 0.9.0