Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-14714

Опубликовано: 15 дек. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's TCC privileges In fixed versions parent-constraints are used to allow only the main application to launch interpreter with those permissions This issue affects LibreOffice on macOS: from 25.2 before < 25.2.4.

РелизСтатусПримечание
devel

not-affected

debian: Only affects LibreOffice on MacOS
esm-infra/focal

not-affected

debian: Only affects LibreOffice on MacOS
jammy

not-affected

debian: Only affects LibreOffice on MacOS
noble

not-affected

debian: Only affects LibreOffice on MacOS
plucky

not-affected

debian: Only affects LibreOffice on MacOS
questing

not-affected

debian: Only affects LibreOffice on MacOS
upstream

not-affected

debian: Only affects LibreOffice on MacOS

Показывать по

EPSS

Процентиль: 4%
0.00018
Низкий

Связанные уязвимости

nvd
около 2 месяцев назад

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's TCC privileges In fixed versions parent-constraints are used to allow only the main application to launch interpreter with those permissions This issue affects LibreOffice on macOS: from 25.2 before < 25.2.4.

debian
около 2 месяцев назад

An Authentication Bypass vulnerability existed where the application b ...

github
около 2 месяцев назад

An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the Transparency, Consent, and Control (TCC) permissions granted by the user to the main application bundle By executing the bundled interpreter directly the attacker's scripts run with the application's TCC privileges In fixed versions parent-constraints are used to allow only the main application to launch interpreter with those permissions This issue affects LibreOffice on macOS: from 25.2 before < 25.2.4.

EPSS

Процентиль: 4%
0.00018
Низкий