CVE-2022-29281

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
15/04/2022
Last modified:
08/08/2023

Description

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:notable:notable:*:*:*:*:*:*:*:* 1.9.0 (excluding)
cpe:2.3:a:notable:notable:1.9.0:beta0:*:*:*:*:*:*
cpe:2.3:a:notable:notable:1.9.0:beta1:*:*:*:*:*:*
cpe:2.3:a:notable:notable:1.9.0:beta2:*:*:*:*:*:*
cpe:2.3:a:notable:notable:1.9.0:beta3:*:*:*:*:*:*
cpe:2.3:a:notable:notable:1.9.0:beta4:*:*:*:*:*:*
cpe:2.3:a:notable:notable:1.9.0:beta5:*:*:*:*:*:*
cpe:2.3:a:notable:notable:1.9.0:beta6:*:*:*:*:*:*
cpe:2.3:a:notable:notable:1.9.0:beta7:*:*:*:*:*:*