CVE-2023-2255
5.3
MEDIUM
CVSS 3.1
EPSS 2.2%
描述
Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affected versions of LibreOffice documents that used "floating frames" linked to external files, would load the contents of those frames without prompting the user for permission to do so. This was inconsistent with the treatment of other linked content in LibreOffice. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.
如何修補 CVE-2023-2255
要修補 CVE-2023-2255,請將受影響套件升級到下列已修補版本。
- —升級至 1:7.0.4-4+deb11u7 或更新版本
CVE-2023-2255 正在被利用嗎?
低 — EPSS 為 2.2%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 1:7.0.4-4+deb11u7
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |