Show plain JSON{"affected_release": [{"advisory": "RHSA-2024:1514", "cpe": "cpe:/a:redhat:enterprise_linux:8", "package": "libreoffice-1:6.4.7.2-16.el8_9", "product_name": "Red Hat Enterprise Linux 8", "release_date": "2024-03-26T00:00:00Z"}, {"advisory": "RHSA-2024:1512", "cpe": "cpe:/a:redhat:rhel_aus:8.2", "package": "libreoffice-1:6.0.6.1-21.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Advanced Update Support", "release_date": "2024-03-26T00:00:00Z"}, {"advisory": "RHSA-2024:1512", "cpe": "cpe:/a:redhat:rhel_tus:8.2", "package": "libreoffice-1:6.0.6.1-21.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Telecommunications Update Service", "release_date": "2024-03-26T00:00:00Z"}, {"advisory": "RHSA-2024:1512", "cpe": "cpe:/a:redhat:rhel_e4s:8.2", "package": "libreoffice-1:6.0.6.1-21.el8_2", "product_name": "Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions", "release_date": "2024-03-26T00:00:00Z"}, {"advisory": "RHSA-2024:1480", "cpe": "cpe:/a:redhat:rhel_aus:8.4", "package": "libreoffice-1:6.4.7.2-16.el8_4", "product_name": "Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support", "release_date": "2024-03-25T00:00:00Z"}, {"advisory": "RHSA-2024:1480", "cpe": "cpe:/a:redhat:rhel_tus:8.4", "package": "libreoffice-1:6.4.7.2-16.el8_4", "product_name": "Red Hat Enterprise Linux 8.4 Telecommunications Update Service", "release_date": "2024-03-25T00:00:00Z"}, {"advisory": "RHSA-2024:1480", "cpe": "cpe:/a:redhat:rhel_e4s:8.4", "package": "libreoffice-1:6.4.7.2-16.el8_4", "product_name": "Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions", "release_date": "2024-03-25T00:00:00Z"}, {"advisory": "RHSA-2024:1473", "cpe": "cpe:/a:redhat:rhel_eus:8.6", "package": "libreoffice-1:6.4.7.2-16.el8_6", "product_name": "Red Hat Enterprise Linux 8.6 Extended Update Support", "release_date": "2024-03-21T00:00:00Z"}, {"advisory": "RHSA-2024:1513", "cpe": "cpe:/a:redhat:rhel_eus:8.8", "package": "libreoffice-1:6.4.7.2-16.el8_8", "product_name": "Red Hat Enterprise Linux 8.8 Extended Update Support", "release_date": "2024-03-26T00:00:00Z"}, {"advisory": "RHSA-2024:1427", "cpe": "cpe:/a:redhat:enterprise_linux:9", "package": "libreoffice-1:7.1.8.1-12.el9_3", "product_name": "Red Hat Enterprise Linux 9", "release_date": "2024-03-19T00:00:00Z"}, {"advisory": "RHSA-2024:3835", "cpe": "cpe:/a:redhat:enterprise_linux:9", "package": "libreoffice-1:7.1.8.1-12.el9_4", "product_name": "Red Hat Enterprise Linux 9", "release_date": "2024-06-11T00:00:00Z"}, {"advisory": "RHSA-2024:1423", "cpe": "cpe:/a:redhat:rhel_eus:9.0", "package": "libreoffice-1:7.1.8.1-12.el9_0", "product_name": "Red Hat Enterprise Linux 9.0 Extended Update Support", "release_date": "2024-03-19T00:00:00Z"}, {"advisory": "RHSA-2024:1425", "cpe": "cpe:/a:redhat:rhel_eus:9.2", "package": "libreoffice-1:7.1.8.1-12.el9_2", "product_name": "Red Hat Enterprise Linux 9.2 Extended Update Support", "release_date": "2024-03-19T00:00:00Z"}], "bugzilla": {"description": "libreoffice: Insufficient macro permission validation leading to macro execution", "id": "2254005", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254005"}, "csaw": false, "cvss3": {"cvss3_base_score": "8.3", "cvss3_scoring_vector": "CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:H", "status": "verified"}, "cwe": "CWE-250", "details": ["Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.\nIn affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.", "An insufficient permission validation vulnerability was found in LibreOffice. In versions that support running commands in hyperlinks, an attacker can execute built-in macros without warning the user."], "name": "CVE-2023-6186", "package_state": [{"cpe": "cpe:/o:redhat:enterprise_linux:6", "fix_state": "Out of support scope", "package_name": "libreoffice", "product_name": "Red Hat Enterprise Linux 6"}, {"cpe": "cpe:/o:redhat:enterprise_linux:7", "fix_state": "Will not fix", "package_name": "libreoffice", "product_name": "Red Hat Enterprise Linux 7"}, {"cpe": "cpe:/o:redhat:enterprise_linux:8", "fix_state": "Not affected", "package_name": "libreoffice:flatpak/libreoffice", "product_name": "Red Hat Enterprise Linux 8"}, {"cpe": "cpe:/o:redhat:enterprise_linux:9", "fix_state": "Not affected", "package_name": "libreoffice:flatpak/libreoffice", "product_name": "Red Hat Enterprise Linux 9"}], "public_date": "2023-12-11T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2023-6186\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-6186\nhttps://www.libreoffice.org/about-us/security/advisories/cve-2023-6186"], "threat_severity": "Important"}