First published: Sat Aug 13 2022(Updated: )
Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26306 - LibreOffice
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache OpenOffice | <4.1.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37400 is a vulnerability in Apache OpenOffice that allows the storage of passwords for web connections in the user's configuration database.
Apache OpenOffice stores passwords for web connections in the user's configuration database.
Yes, the stored passwords in Apache OpenOffice are encrypted with a single master key provided by the user.
The severity of CVE-2022-37400 is high, with a CVSS score of 8.8.
To fix CVE-2022-37400, users should update to Apache OpenOffice version 4.1.14 or later, which contains the necessary patch to address the vulnerability.