Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6pv-x5p3-8fv6

Опубликовано: 16 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.6
CVSS3: 6.8

Описание

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

7.6 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 6.8
nvd
1 день назад

Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent documents. Attackers with revoked access can retain real-time read and write access to sub-documents through open websocket sessions that are never disconnected.

7.6 High

CVSS4

6.8 Medium

CVSS3

Дефекты

CWE-613