libreoffice libreoffice CVE-2022-26307 vulnerability in LibreOffice and Other Products
Published on July 25, 2022

Weak Master Keys

product logo product logo product logo
LibreOffice supports the storage of passwords for web connections in the users configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force attack if an attacker has access to the users stored config. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.3.

NVD

Weakness Type

Inadequate Encryption Strength

The software stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required. A weak encryption scheme can be subjected to brute force attacks that have a reasonable chance of succeeding using current attack methods and resources.


Products Associated with CVE-2022-26307

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-26307 are published in these products:

 
 
 

Affected Versions

The Document Foundation LibreOffice:

Exploit Probability

EPSS
1.35%
Percentile
69.99%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.