2024-05-14 22:03:31 +00:00
{
"id" : "CVE-2024-3044" ,
"sourceIdentifier" : "security@documentfoundation.org" ,
"published" : "2024-05-14T21:15:12.627" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T09:28:45.103" ,
2024-05-15 18:03:29 +00:00
"vulnStatus" : "Awaiting Analysis" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-05-14 22:03:31 +00:00
"descriptions" : [
{
"lang" : "en" ,
2024-09-20 12:03:18 +00:00
"value" : "Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted."
2024-05-15 18:03:29 +00:00
} ,
{
"lang" : "es" ,
"value" : "La ejecuci\u00f3n de script sin marcar en el enlace gr\u00e1fico al hacer clic en las versiones afectadas de LibreOffice permite a un atacante crear un documento que, sin aviso, ejecutar\u00e1 script integradas en LibreOffice al hacer clic en un gr\u00e1fico. Anteriormente, estos scripts se consideraban confiables, pero ahora se consideran no confiables."
2024-05-14 22:03:31 +00:00
}
] ,
2024-11-12 23:03:21 +00:00
"metrics" : {
"cvssMetricV31" : [
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 6.5 ,
"baseSeverity" : "MEDIUM" ,
2024-11-12 23:03:21 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "LOW" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "LOW"
2024-11-12 23:03:21 +00:00
} ,
"exploitabilityScore" : 3.9 ,
"impactScore" : 2.5
}
]
} ,
2024-05-14 22:03:31 +00:00
"weaknesses" : [
{
"source" : "security@documentfoundation.org" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
2024-09-20 12:03:18 +00:00
"value" : "CWE-356"
2024-05-14 22:03:31 +00:00
}
]
2024-11-12 23:03:21 +00:00
} ,
{
"source" : "134c704f-9b21-4f2e-91b3-4a467353bcc0" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-94"
}
]
2024-05-14 22:03:31 +00:00
}
] ,
"references" : [
2024-06-10 18:03:10 +00:00
{
"url" : "https://lists.debian.org/debian-lts-announce/2024/05/msg00016.html" ,
"source" : "security@documentfoundation.org"
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TU3TYDXICKPYHMCNL7ARYYBXACEAYJ4/" ,
"source" : "security@documentfoundation.org"
} ,
2024-05-14 22:03:31 +00:00
{
"url" : "https://www.libreoffice.org/about-us/security/advisories/CVE-2024-3044" ,
"source" : "security@documentfoundation.org"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://lists.debian.org/debian-lts-announce/2024/05/msg00016.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TU3TYDXICKPYHMCNL7ARYYBXACEAYJ4/" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://www.libreoffice.org/about-us/security/advisories/CVE-2024-3044" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2024-05-14 22:03:31 +00:00
}
]
}