Back

HIGH

Ability to trust not validated macro signatures removed in high security mode

Published Aug 5, 2024

Description

Certificate Validation user interface in LibreOffice allows potential vulnerability.

Signed macros are scripts that have been digitally signed by the developer using a cryptographic signature. When a document with a signed macro is opened a warning is displayed by LibreOffice before the macro is executed.

Previously if verification failed the user could fail to understand the failure and choose to enable the macros anyway.

This issue affects LibreOffice: from 24.2 before 24.2.5.

Affected products

Remediation

Red Hat statement

This vulnerability requires an unlikely configuration (UX confusion on the user's part, i.e. ignoring the warning, not understanding the failure, etc.) to be actionable. As such, Red Hat considers this to be a moderate vulnerability and not an important one, per our CVE classification policy.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Document Fdn.
Published Aug 5, 2024
Updated Aug 5, 2024
Reserved Jul 3, 2024
CISA Vulnrichment
Updated Aug 5, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Aug 5, 2024
ENISA EUVD
Assigner Document Fdn.
Published Aug 5, 2024
Updated Aug 5, 2024
Exploited since n/a
EUVD-2024-47565