CyberRota Analysis
AI-GeneratedLibreOffice Calc is vulnerable due to its ability to link cell ranges to external data sources, potentially allowing malicious Java database drivers to be loaded from remote locations when a document is opened. This could lead to the execution of arbitrary Java code, posing significant security risks to users. Organizations using LibreOffice, especially those handling sensitive data, should prioritize applying the latest updates to mitigate this high-severity vulnerability.
Original NVD Description
LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed versions an entry in a Java class path has to be a file URL.