CVE-2022-26306


Execution of Untrusted Macros Due to Improper Certificate Validation

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where the required initialization vector for encryption was always the same which weakens the security of the encryption making them vulnerable if an attacker has access to the user's configuration data. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.



We have discovered 108 live websites that are affected by CVE-2022-26306.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 7.2 before 7.2.7
  • from 7.3 before 7.3.1
Total Vulnerable Versions195
Vulnerable Domains108 live websites (3.20% of LibreOffice install base)


Common Weakness Enumeration


CWE-326 Inadequate Encryption Strength



Details

  • Published - Jul 25, 2022
  • Updated - Mar 26, 2023

Credits

  • OpenSource Security GmbH on behalf of the German Federal Office for Information Security





Countries

United States19 websites



Germany35 websites
France12 websites
GB7 websites
Argentina3 websites
China3 websites
Hungary3 websites
Russia3 websites
Austria2 websites

TLDs

.de24 websites
.com23 websites
.org9 websites
.fr8 websites
.co.uk5 websites
.net5 websites
.ru3 websites
.at2 websites
.nl2 websites
.cn2 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2022-26306

Top websites that are affected by CVE-2022-26306. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.***.cn China*,***,***
************.de Germany*,***,***
******.*********.de Germany*,***,***
***********.com *,***,***
****************************.de Germany*,***,***
***.*******.com United States*,***,***
***.***.cn China*,***,***
****.org United States*,***,***
****************.de Germany*,***,***
**************.net Germany*,***,***
See full domain list