CVE-2022-26307 is a high-severity vulnerability affecting LibreOffice versions prior to 7.2.7 and 7.3.3. A flaw in the master key's encoding reduced its entropy from 128 to 43 bits, making stored web connection passwords susceptible to brute-force attacks if an attacker gains access to the user's configuration. With a CVSS score of 8.8, this vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB) is currently unavailable. The vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.2.0, < 7.2.7CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* | ||
>= 7.3.0, < 7.3.3CPE matchmatch criteria | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
>= 7.2, < 7.2.7CPE match | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* | ||
>= 7.3, < 7.3.3CPE match | cpe:2.3:a:libreoffice:libreoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.