Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).
References
Link | Resource |
---|---|
https://github.com/notable/notable-insiders/releases/tag/v1.9.0-beta.8 | Release Notes Third Party Advisory |
https://github.com/hmnthabit/Advisories/blob/master/CVE-2022-29281.md | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-04-15 14:15
Updated : 2022-12-02 14:41
NVD link : CVE-2022-29281
Mitre link : CVE-2022-29281
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
notable
- notable