Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).
References
Link | Resource |
---|---|
https://github.com/hmnthabit/Advisories/blob/master/CVE-2022-29281.md | Third Party Advisory |
https://github.com/notable/notable-insiders/releases/tag/v1.9.0-beta.8 | Release Notes Third Party Advisory |
https://github.com/hmnthabit/Advisories/blob/master/CVE-2022-29281.md | Third Party Advisory |
https://github.com/notable/notable-insiders/releases/tag/v1.9.0-beta.8 | Release Notes Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/hmnthabit/Advisories/blob/master/CVE-2022-29281.md - Third Party Advisory | |
References | () https://github.com/notable/notable-insiders/releases/tag/v1.9.0-beta.8 - Release Notes, Third Party Advisory |
08 Aug 2023, 14:22
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-22 |
Information
Published : 2022-04-15 21:15
Updated : 2024-11-21 06:58
NVD link : CVE-2022-29281
Mitre link : CVE-2022-29281
CVE.ORG link : CVE-2022-29281
JSON object : View
Products Affected
notable
- notable
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')