Currently the following Collabora Online versions are supported with security updates.
| Version | Supported |
|---|---|
| 26.04.x | ✅ |
| 25.04.x | ✅ |
| 24.04.x | ✅ |
| 23.05.x or older | ❌ |
- Share the details of the vulnerability privately with our security team by emailing officesecurity@lists.freedesktop.org.
- We acknowledge your report and then verify the vulnerability.
- Our policy is to disclose the vulnerability to the public within 30 days of the release of the fix, as an advisory with a CVE ID at https://github.com/CollaboraOnline/online/security/advisories.
- We credit reporters in the advisory, but reporters may remain anonymous if they wish.
We fix these as ordinary bugs, without a CVE:
- Denial of service on its own, including crashes, hangs and resource exhaustion. If it leads to something more, such as code execution or data disclosure, we assess that instead.
- Missing hardening with no demonstrated exploit.