Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-26306

Опубликовано: 25 июл. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

РелизСтатусПримечание
bionic

released

1:6.0.7-0ubuntu0.18.04.12
devel

not-affected

esm-infra/focal

not-affected

1:6.4.7-0ubuntu0.20.04.5
focal

released

1:6.4.7-0ubuntu0.20.04.5
jammy

not-affected

1:7.3.3-0ubuntu0.22.04.1
kinetic

not-affected

lunar

not-affected

trusty

ignored

end of standard support
upstream

released

1:7.3.3~rc1-2
xenial

ignored

end of standard support

Показывать по

EPSS

Процентиль: 60%
0.00396
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 3 лет назад

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

CVSS3: 7.5
nvd
около 3 лет назад

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

CVSS3: 7.5
debian
около 3 лет назад

LibreOffice supports the storage of passwords for web connections in t ...

CVSS3: 7.5
github
около 3 лет назад

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

CVSS3: 7.5
fstec
около 3 лет назад

Уязвимость базы данных конфигураций пользователя пакета офисных программ LibreOffice, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 60%
0.00396
Низкий

7.5 High

CVSS3