CVE-2021-41830

CWE-3473 documents3 sources
Severity
7.5HIGH
EPSS
0.8%
top 26.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateMay 24

Description

It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source. All versions of Apache OpenOffice up to 4.1.10 are affected. Users are advised to update to version 4.1.11. See CVE-2021-25633 for the LibreOffice advisory.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/openoffice< 4.1.11
CVEListV5apache_software_foundation/apache_openofficeApache OpenOffice4.1.10+1

🔴Vulnerability Details

2
GHSA
GHSA-7qhr-g3xw-3692: It is possible for an attacker to manipulate signed documents and macros to appear to come from a trusted source2022-05-24
CVEList
Double Certificate Attack2021-10-11
CVE-2021-41830 (HIGH CVSS 7.5) | It is possible for an attacker to m | cvebase.io