---
title: "CVE-2023-2255\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2023-2255?format=md
keywords: index, follow
---

# CVE-2023-2255

Publication date 25 May 2023

Last updated 26 August 2025

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**5.3 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2023-2255?format=md#impact-score)

Toggle side navigation

## Description

Improper access control in editor components of The Document Foundation
LibreOffice allowed an attacker to craft a document that would cause
external links to be loaded without prompt. In the affected versions of
LibreOffice documents that used "floating frames" linked to external files,
would load the contents of those frames without prompting the user for
permission to do so. This was inconsistent with the treatment of other
linked content in LibreOffice. This issue affects: The Document Foundation
LibreOffice 7.4 versions prior to 7.4.7; 7.5 versions prior to 7.5.3.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| libreoffice | 23.04 lunar | Fixed 4:7.5.3-0ubuntu0.23.04.1 |
| 22.10 kinetic | Fixed 1:7.4.7-0ubuntu0.22.10.1 |
| 22.04 LTS jammy | Fixed 1:7.3.7-0ubuntu0.22.04.3 |
| 20.04 LTS focal | Fixed 1:6.4.7-0ubuntu0.20.04.8 |
| 18.04 LTS bionic | Ignored end of standard support, was needed |
| 16.04 LTS xenial | Ignored end of standard support |
| 14.04 LTS trusty | Ignored end of standard support |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

5.3 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | Low |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 5.3 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-2255)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2023-2255)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2023-2255)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2023-2255)

### Related Ubuntu Security Notices (USN)

+ [USN-6144-1](https://usn.ubuntu.com/USN-6144-1)
+ LibreOffice vulnerabilities
+ 7 June 2023

### Other references

* <https://www.libreoffice.org/about-us/security/advisories/CVE-2023-2255>
* <https://www.cve.org/CVERecord?id=CVE-2023-2255>
