cbcvebase.
CVE-2022-38745
published 2023-03-24

CVE-2022-38745: Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.

Affected

7 ranges
VendorProductVersion rangeFixed in
apacheopenoffice< 4.1.144.1.14
apache_software_foundationapache_openoffice< 4.1.144.1.14
debianlibreoffice< libreoffice 1:7.3.1-1 (bookworm)libreoffice 1:7.3.1-1 (bookworm)
libreofficelibreoffice>= 0 < 1:7.0.4-4+deb11u61:7.0.4-4+deb11u6
libreofficelibreoffice>= 0 < 1:7.3.1-11:7.3.1-1
libreofficelibreoffice>= 0 < 1:7.3.1-11:7.3.1-1
libreofficelibreoffice>= 0 < 1:7.3.1-11:7.3.1-1

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH