PT-2022-23974 · Apache · Apache Openoffice+1
Selma Jabour
·
Published
2022-08-13
·
Updated
2023-08-02
·
CVE-2022-37401
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache OpenOffice versions prior to 4.1.13
Description
A flaw in Apache OpenOffice exists where the master key used for encrypting stored passwords is poorly encoded, reducing its entropy from 128 to 43 bits. This makes the stored passwords vulnerable to a brute force attack if an attacker gains access to the user's stored configuration.
Recommendations
For versions prior to 4.1.13, update to version 4.1.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the configuration database to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Openoffice
Openoffice