CVE Vulnerabilities

CVE-2023-6186

Improper Preservation of Permissions

Published: Dec 11, 2023 | Modified: Feb 13, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
8.3 IMPORTANT
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.

In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

NameVendorStart VersionEnd Version
LibreofficeLibreoffice7.5.0 (including)7.5.9 (excluding)
LibreofficeLibreoffice7.6.0 (including)7.6.4 (excluding)
Red Hat Enterprise Linux 8RedHatlibreoffice-1:6.4.7.2-16.el8_9*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatlibreoffice-1:6.0.6.1-21.el8_2*
Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceRedHatlibreoffice-1:6.0.6.1-21.el8_2*
Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsRedHatlibreoffice-1:6.0.6.1-21.el8_2*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatlibreoffice-1:6.4.7.2-16.el8_4*
Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceRedHatlibreoffice-1:6.4.7.2-16.el8_4*
Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsRedHatlibreoffice-1:6.4.7.2-16.el8_4*
Red Hat Enterprise Linux 8.6 Extended Update SupportRedHatlibreoffice-1:6.4.7.2-16.el8_6*
Red Hat Enterprise Linux 8.8 Extended Update SupportRedHatlibreoffice-1:6.4.7.2-16.el8_8*
Red Hat Enterprise Linux 9RedHatlibreoffice-1:7.1.8.1-12.el9_3*
Red Hat Enterprise Linux 9RedHatlibreoffice-1:7.1.8.1-12.el9_4*
Red Hat Enterprise Linux 9.0 Extended Update SupportRedHatlibreoffice-1:7.1.8.1-12.el9_0*
Red Hat Enterprise Linux 9.2 Extended Update SupportRedHatlibreoffice-1:7.1.8.1-12.el9_2*
LibreofficeUbuntubionic*
LibreofficeUbuntudevel*
LibreofficeUbuntuesm-infra/focal*
LibreofficeUbuntufocal*
LibreofficeUbuntujammy*
LibreofficeUbuntulunar*
LibreofficeUbuntumantic*
LibreofficeUbuntutrusty*
LibreofficeUbuntuupstream*
LibreofficeUbuntuxenial*

References