CVE-2021-41832: Content Manipulation with Certificate Validation Attack
It is possible for an attacker to manipulate documents to appear to be signed by a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25635 for the LibreOffice advisory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
apache/openofficeto a version that resolves this vulnerability.Fixed in 4.1.11 - Compensating control
CVE-2021-25635 (LibreOffice advisory) references the same certificate validation/content manipulation issue; ensure any documented mitigations from that advisory are applied alongside upgrading OpenOffice to 4.1.11.
Event History
Frequently Asked Questions
What is CVE-2021-41832?
CVE-2021-41832 is a vulnerability that allows an attacker to manipulate documents to appear as if they are signed by a trusted source in Apache OpenOffice.
Which versions of Apache OpenOffice are affected by CVE-2021-41832?
All versions of Apache OpenOffice up to 4.1.10 are affected by CVE-2021-41832.
How can an attacker exploit CVE-2021-41832?
An attacker can manipulate documents to appear to be signed by a trusted source, potentially tricking users into believing the documents are legitimate.
What is the severity of CVE-2021-41832?
CVE-2021-41832 has a severity rating of 7.5 (High).
How can I mitigate CVE-2021-41832?
Users are advised to update Apache OpenOffice to version 4.1.11 to mitigate CVE-2021-41832.