CVE-2022-3140 - LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or activated by document events, could result in arbitrary script execution without warning. Fixed in: LibreOffice 7.3.6/7.4.1 In versions >= 7.3.6 (and >= 7.4.1) such unwanted command URIs are blocked from execution. Reference: https://www.libreoffice.org/about-us/security/advisories/CVE-2022-3140
Created libreoffice tracking bugs for this issue: Affects: fedora-all [bug 2134698]
<iframe src='macro:Shell("/usr/bin/xeyes")'></iframe> triggers the vulnerability on libreoffice-5.3.6.1-25.el7_9.x86_64
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:0089 https://access.redhat.com/errata/RHSA-2023:0089
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:0304 https://access.redhat.com/errata/RHSA-2023:0304
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-3140