← Back to CVE List
Vulnerability Intelligence Report
TLS certificate are not properly verified when utilizing LibreOfficeKit

CVE-2024-5261

Improper Certificate Validation vulnerability in LibreOffice "LibreOfficeKit" mode disables TLS certification verification LibreOfficeKit can be used for accessing LibreOffice functionality through C/C++. Typically this is used by third party components to reuse LibreOffice as a library to convert, view or otherwise interact with documents. LibreOffice internally makes use of "curl" to fetch remote resources such as images hosted on webservers. In affected versions of LibreOffice, when used in LibreOfficeKit mode only, then curl's TLS certification verification was disabled (CURLOPT_SSL_VERIFYPEER of false) In the fixed versions curl operates in LibreOfficeKit mode the same as in standard mode with CURLOPT_SSL_VERIFYPEER of true. This issue affects LibreOffice before version 24.2.4.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
EPSS Probability:0.43%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-295 ↗CWE-295 Improper Certificate Validation

Affected Products & Versions

Vendor Product Affected Versions
The Document Foundation LibreOffice 24.2 < 24.2.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.428%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityDocument Fdn.
Reserved2024-05-23T07:20:08
Published2024-06-25T12:44:24
Patch Date2024-06-25
Last Updated2024-08-01T21:11:11

LINK COPIED TO CLIPBOARD