CVE-2022-29281
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
15/04/2022
Last modified:
08/08/2023
Description
Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:notable:notable:*:*:*:*:*:*:*:* | 1.9.0 (excluding) | |
| cpe:2.3:a:notable:notable:1.9.0:beta0:*:*:*:*:*:* | ||
| cpe:2.3:a:notable:notable:1.9.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:notable:notable:1.9.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:notable:notable:1.9.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:notable:notable:1.9.0:beta4:*:*:*:*:*:* | ||
| cpe:2.3:a:notable:notable:1.9.0:beta5:*:*:*:*:*:* | ||
| cpe:2.3:a:notable:notable:1.9.0:beta6:*:*:*:*:*:* | ||
| cpe:2.3:a:notable:notable:1.9.0:beta7:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



