Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.
In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
| Software | From | Fixed in |
|---|---|---|
| libreoffice / libreoffice | 7.5.0 | 7.5.9 |
| libreoffice / libreoffice | 7.6.0 | 7.6.4 |
| fedoraproject / fedora | 38 | 38.x |
| debian / debian_linux | 11.0 | 11.0.x |
| debian / debian_linux | 12.0 | 12.0.x |