Description
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
Published: 2023-05-25
Score: 5.3 Medium
EPSS: 42.5% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-3526-1 libreoffice security update
Debian DSA Debian DSA DSA-5415-1 libreoffice security update
Ubuntu USN Ubuntu USN USN-6144-1 LibreOffice vulnerabilities
History

No history.

Subscriptions

Debian Debian Linux
Libreoffice Libreoffice
Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: Document Fdn.

Published:

Updated: 2024-08-02T06:19:14.082Z

Reserved: 2023-04-24T00:00:00.000Z

Link: CVE-2023-2255

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-05-25T20:15:09.350

Modified: 2024-11-21T07:58:14.943

Link: CVE-2023-2255

cve-icon Redhat

Severity : Moderate

Publid Date: 2023-05-25T00:00:00Z

Links: CVE-2023-2255 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses