CVE Database
/

CVE-2022-37401

Back to search

CVE-2022-37401

Published: Aug 13, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Apache OpenOffice supports the storage of passwords for web connections in the user's configuration database. The stored passwords are encrypted with a single master key provided by the user. A flaw in OpenOffice existed where master key was poorly encoded resulting in weakening its entropy from 128 to 43 bits making the stored passwords vulnerable to a brute force attack if an attacker has access to the users stored config. This issue affects: Apache OpenOffice versions prior to 4.1.13. Reference: CVE-2022-26307 - LibreOffice

VendorProductVersions

Apache Software Foundation

Apache OpenOffice

affected
Apache OpenOffice 4 - < 4.1.13

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now