Exposure of Environmental Variables in LibreOffice by The Document Foundation
CVE-2024-12426
6.7MEDIUM
What is CVE-2024-12426?
The vulnerability presents a significant risk within LibreOffice, allowing unauthorized actors to expose environmental variables and arbitrary INI file values. By exploiting this flaw, an attacker could potentially exfiltrate sensitive information to a remote server upon the opening of specially crafted documents containing URLs. This vulnerability affects versions of LibreOffice prior to 24.8.4, highlighting the importance of keeping software updated and exercising caution with document sources.
Affected Version(s)
LibreOffice 24.8
