CVE-2022-37401 describes a weakness in Apache OpenOffice versions prior to 4.1.13 where the master key used to encrypt stored web connection passwords was poorly encoded, reducing its entropy from 128 to 43 bits. This flaw makes user passwords vulnerable to brute-force attacks if an attacker gains access to the user's configuration files. Rated with a CVSS score of 8.8 (High), this vulnerability allows for high impact to confidentiality, integrity, and availability with low attack complexity and requires local access. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.13CPE matchmatch criteria | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.