CVE-2022-26307


Weak Master Keys

LibreOffice supports the storage of passwords for web connections in the user’s configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in LibreOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulerable to a brute force attack if an attacker has access to the users stored config. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.3.



We have discovered 151 live websites that are affected by CVE-2022-26307.

Contact us to get more info




Affected Software

Product  LibreOffice
Category Content Management System
Vulnerable Versions
  • from 7.2 before 7.2.7
  • from 7.3 before 7.3.3
Total Vulnerable Versions195
Vulnerable Domains151 live websites (4.48% of LibreOffice install base)


Common Weakness Enumeration


CWE-326 Inadequate Encryption Strength



Details

  • Published - Jul 25, 2022
  • Updated - Mar 26, 2023

Credits

  • OpenSource Security GmbH on behalf of the German Federal Office for Information Security





Countries

United States28 websites



Germany48 websites
France15 websites
GB8 websites
Russia4 websites
Argentina3 websites
Austria3 websites
Canada3 websites
China3 websites
Denmark3 websites

TLDs

.com36 websites
.de35 websites
.org12 websites
.fr8 websites
.net5 websites
.co.uk5 websites
.info4 websites
.at3 websites
.ru3 websites
.dk3 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


References


Websites affected by CVE-2022-26307

Top websites that are affected by CVE-2022-26307. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.*******.org United States*,***,***
******.***.cn China*,***,***
************.de Germany*,***,***
*****.dk Denmark*,***,***
******.*********.de Germany*,***,***
***********.com *,***,***
***.******.com United States*,***,***
****************************.de Germany*,***,***
***.*******.com United States*,***,***
***.***.cn China*,***,***
See full domain list