Search

Find a vulnerability

Search criteria

    2 vulnerabilities by the_document_foundation

    CVE-2024-6472 (GCVE-0-2024-6472)

    Vulnerability from nvd – Published: 2024-08-05 12:55 – Updated: 2024-08-05 14:32
    VLAI
    Title
    Ability to trust not validated macro signatures removed in high security mode
    Summary
    Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro is executed. Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway. This issue affects LibreOffice: from 24.2 before 24.2.5.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-05 14:28 UTC
    CWE
    • CWE-295 - Improper Certificate Validation
    Impacted products
    Vendor Product Version
    The Document Foundation LibreOffice Affected: 24.2 , < 24.2.5 (24.2 series)
    Create a notification for this product.
    the_document_foundation libreoffice Affected: 24.2 , < 24.2.5 (custom)
        cpe:2.3:a:the_document_foundation:libreoffice:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-08-05 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:the_document_foundation:libreoffice:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "libreoffice",
                "vendor": "the_document_foundation",
                "versions": [
                  {
                    "lessThan": "24.2.5",
                    "status": "affected",
                    "version": "24.2",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6472",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-05T14:28:03.223479Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-05T14:32:48.640Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "LibreOffice",
              "vendor": "The Document Foundation",
              "versions": [
                {
                  "lessThan": "24.2.5",
                  "status": "affected",
                  "version": "24.2",
                  "versionType": "24.2 series"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Thanks to OpenSource Security GmbH on behalf of the German Federal Office for Information Security"
            }
          ],
          "datePublic": "2024-08-05T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eCertificate Validation user interface in LibreOffice allows potential vulnerability.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eSigned macros are scripts that have been digitally signed by the \ndeveloper using a cryptographic signature. When a document with a signed\n macro is opened a warning is displayed by LibreOffice before the macro \nis executed.\u003cbr\u003e\u003cbr\u003ePreviously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.\u003cbr\u003e\u003c/div\u003e\u003cp\u003eThis issue affects LibreOffice: from 24.2 before 24.2.5.\u003c/p\u003e"
                }
              ],
              "value": "Certificate Validation user interface in LibreOffice allows potential vulnerability.\n\n\n\n\nSigned macros are scripts that have been digitally signed by the \ndeveloper using a cryptographic signature. When a document with a signed\n macro is opened a warning is displayed by LibreOffice before the macro \nis executed.\n\nPreviously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.\n\n\nThis issue affects LibreOffice: from 24.2 before 24.2.5."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-21",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-21 Exploitation of Trusted Identifiers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper Certificate Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-05T12:55:39.199Z",
            "orgId": "4fe7d05b-1353-44cc-8b7a-1e416936dff2",
            "shortName": "Document Fdn."
          },
          "references": [
            {
              "url": "https://www.libreoffice.org/about-us/security/advisories/CVE-2024-6472"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Ability to trust not validated macro signatures removed in high security mode",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fe7d05b-1353-44cc-8b7a-1e416936dff2",
        "assignerShortName": "Document Fdn.",
        "cveId": "CVE-2024-6472",
        "datePublished": "2024-08-05T12:55:39.199Z",
        "dateReserved": "2024-07-03T09:26:27.358Z",
        "dateUpdated": "2024-08-05T14:32:48.640Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6472 (GCVE-0-2024-6472)

    Vulnerability from cvelistv5 – Published: 2024-08-05 12:55 – Updated: 2024-08-05 14:32
    VLAI
    Title
    Ability to trust not validated macro signatures removed in high security mode
    Summary
    Certificate Validation user interface in LibreOffice allows potential vulnerability. Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro is executed. Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway. This issue affects LibreOffice: from 24.2 before 24.2.5.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-05 14:28 UTC
    CWE
    • CWE-295 - Improper Certificate Validation
    Impacted products
    Vendor Product Version
    The Document Foundation LibreOffice Affected: 24.2 , < 24.2.5 (24.2 series)
    Create a notification for this product.
    the_document_foundation libreoffice Affected: 24.2 , < 24.2.5 (custom)
        cpe:2.3:a:the_document_foundation:libreoffice:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Date Public
    2024-08-05 12:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:the_document_foundation:libreoffice:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "libreoffice",
                "vendor": "the_document_foundation",
                "versions": [
                  {
                    "lessThan": "24.2.5",
                    "status": "affected",
                    "version": "24.2",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6472",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-05T14:28:03.223479Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-05T14:32:48.640Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "LibreOffice",
              "vendor": "The Document Foundation",
              "versions": [
                {
                  "lessThan": "24.2.5",
                  "status": "affected",
                  "version": "24.2",
                  "versionType": "24.2 series"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Thanks to OpenSource Security GmbH on behalf of the German Federal Office for Information Security"
            }
          ],
          "datePublic": "2024-08-05T12:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cdiv\u003eCertificate Validation user interface in LibreOffice allows potential vulnerability.\u003c/div\u003e\u003cdiv\u003e\u003cbr\u003e\u003c/div\u003e\u003cdiv\u003eSigned macros are scripts that have been digitally signed by the \ndeveloper using a cryptographic signature. When a document with a signed\n macro is opened a warning is displayed by LibreOffice before the macro \nis executed.\u003cbr\u003e\u003cbr\u003ePreviously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.\u003cbr\u003e\u003c/div\u003e\u003cp\u003eThis issue affects LibreOffice: from 24.2 before 24.2.5.\u003c/p\u003e"
                }
              ],
              "value": "Certificate Validation user interface in LibreOffice allows potential vulnerability.\n\n\n\n\nSigned macros are scripts that have been digitally signed by the \ndeveloper using a cryptographic signature. When a document with a signed\n macro is opened a warning is displayed by LibreOffice before the macro \nis executed.\n\nPreviously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.\n\n\nThis issue affects LibreOffice: from 24.2 before 24.2.5."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-21",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-21 Exploitation of Trusted Identifiers"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-295",
                  "description": "CWE-295 Improper Certificate Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-08-05T12:55:39.199Z",
            "orgId": "4fe7d05b-1353-44cc-8b7a-1e416936dff2",
            "shortName": "Document Fdn."
          },
          "references": [
            {
              "url": "https://www.libreoffice.org/about-us/security/advisories/CVE-2024-6472"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "Ability to trust not validated macro signatures removed in high security mode",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "4fe7d05b-1353-44cc-8b7a-1e416936dff2",
        "assignerShortName": "Document Fdn.",
        "cveId": "CVE-2024-6472",
        "datePublished": "2024-08-05T12:55:39.199Z",
        "dateReserved": "2024-07-03T09:26:27.358Z",
        "dateUpdated": "2024-08-05T14:32:48.640Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }