CVE-2022-29281

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-29281
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-29281.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-29281
Published
2022-04-15T21:15:08Z
Modified
2025-05-28T10:29:30.551017Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

References

Affected packages

Git / github.com/notable/notable-insiders

Affected ranges

Type
GIT
Repo
https://github.com/notable/notable-insiders
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v1.*

v1.9.0-alpha.0
v1.9.0-alpha.1
v1.9.0-alpha.10
v1.9.0-alpha.11
v1.9.0-alpha.12
v1.9.0-alpha.13
v1.9.0-alpha.14
v1.9.0-alpha.15
v1.9.0-alpha.16
v1.9.0-alpha.17
v1.9.0-alpha.18
v1.9.0-alpha.19
v1.9.0-alpha.2
v1.9.0-alpha.20
v1.9.0-alpha.3
v1.9.0-alpha.4
v1.9.0-alpha.5
v1.9.0-alpha.6
v1.9.0-alpha.7
v1.9.0-alpha.8
v1.9.0-alpha.9