Apache OpenOffice versions before 4.1.14 may be configured to add an empty entry to the Java class path. This may lead to run arbitrary Java code from the current directory.
References
Link | Resource |
---|---|
https://lists.apache.org/thread/q3noq7m681kvtb29m28x74q8cnwnzzo0 | Mailing List Vendor Advisory |
https://www.openoffice.org/security/cves/CVE-2022-38745.html | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-03-24 16:15
Updated : 2023-11-07 03:50
NVD link : CVE-2022-38745
Mitre link : CVE-2022-38745
CVE.ORG link : CVE-2022-38745
JSON object : View
Products Affected
apache
- openoffice