CVE-2023-27035

An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:obsidian:obsidian:1.1.9:*:*:*:*:*:*:*

History

21 Nov 2024, 07:52

Type Values Removed Values Added
References () https://forum.obsidian.md/t/embedded-web-pages-in-obsidian-canvas-can-use-sensitive-web-apis-without-the-users-permission-grant/54509 - Exploit () https://forum.obsidian.md/t/embedded-web-pages-in-obsidian-canvas-can-use-sensitive-web-apis-without-the-users-permission-grant/54509 - Exploit
References () https://forum.obsidian.md/t/obsidian-release-v1-1-14-insider-build/54595 - Release Notes () https://forum.obsidian.md/t/obsidian-release-v1-1-14-insider-build/54595 - Release Notes
References () https://github.com/fivex3/CVE-2023-27035 - Exploit, Third Party Advisory () https://github.com/fivex3/CVE-2023-27035 - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5

Information

Published : 2023-05-01 22:15

Updated : 2024-11-21 07:52


NVD link : CVE-2023-27035

Mitre link : CVE-2023-27035

CVE.ORG link : CVE-2023-27035


JSON object : View

Products Affected

obsidian

  • obsidian
CWE
CWE-276

Incorrect Default Permissions