Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/q3noq7m681kvtb29m28x74q8cnwnzzo0 | Mailing List Vendor Advisory |
https://www.openoffice.org/security/cves/CVE-2022-38745.html | Vendor Advisory |
Configurations
History
28 Mar 2023, 21:37
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
References | (MISC) https://lists.apache.org/thread/q3noq7m681kvtb29m28x74q8cnwnzzo0 - Mailing List, Vendor Advisory | |
References | (MISC) https://www.openoffice.org/security/cves/CVE-2022-38745.html - Vendor Advisory | |
CPE | cpe:2.3:a:apache:openoffice:*:*:*:*:*:*:*:* |
24 Mar 2023, 17:57
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-03-24 16:15
Updated : 2024-02-04 23:37
NVD link : CVE-2022-38745
Mitre link : CVE-2022-38745
CVE.ORG link : CVE-2022-38745
JSON object : View
Products Affected
apache
- openoffice