CVE-2023-26435

Published Jun 20, 2023

Last updated 3 months ago

Overview

Description
It was possible to call filesystem and network references using the local LibreOffice instance using manipulated ODT documents. Attackers could discover restricted network topology and services as well as including local files with read permissions of the open-xchange system user. This was limited to specific file-types, like images. We have improved existing content filters and validators to avoid including any local resources. No publicly available exploits are known.
Source
security@open-xchange.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
5
Impact score
1.4
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Severity
MEDIUM

Weaknesses

security@open-xchange.com
CWE-918
nvd@nist.gov
CWE-918

Social media

Hype score
Not currently trending

Configurations