CVE-2024-12426

Severity
6.7MEDIUM
EPSS
0.5%
top 33.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 7
Latest updateJan 27

Description

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. This issue affects LibreOffice: from 24.8 before < 24.8.4.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

Affected Packages4 packages

CVEListV5the_document_foundation/libreoffice24.8< 24.8.4
NVDlibreoffice/libreoffice24.8.0.124.8.4+1
Debianlibreoffice< 1:7.0.4-4+deb11u12+3

Also affects: Debian Linux 11.0

🔴Vulnerability Details

4
OSV
libreoffice vulnerabilities2025-01-27
OSV
CVE-2024-12426: Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice2025-01-07
GHSA
GHSA-x7m8-vrfv-272v: Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice2025-01-07
CVEList
URL fetching can be used to exfiltrate arbitrary INI file values and environment variables2025-01-07

📋Vendor Advisories

3
Ubuntu
LibreOffice vulnerabilities2025-01-27
Red Hat
LibreOffice: URL fetching can be used to exfiltrate arbitrary INI file values and environment variables2025-01-07
Debian
CVE-2024-12426: libreoffice - Exposure of Environmental Variables and arbitrary INI file values to an Unauthor...2024
CVE-2024-12426 (MEDIUM CVSS 6.7) | Exposure of Environmental Variables | cvebase.io