Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-6678211C-BD47-11ED-BEB0-1C1B0D9EA7E6 (CVE-2022-37400): Apache OpenOffice -- master password vulnerabilities

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

FreeBSD: VID-6678211C-BD47-11ED-BEB0-1C1B0D9EA7E6 (CVE-2022-37400): Apache OpenOffice -- master password vulnerabilities

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
02/25/2022
Created
03/13/2023
Added
03/09/2023
Modified
03/09/2023

Description

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26306 - LibreOffice

Solution(s)

  • freebsd-upgrade-package-apache-openoffice
  • freebsd-upgrade-package-apache-openoffice-devel

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;