Obsidian kayıtları
obsidian üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %33,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-20 Improper Input Validation1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-276 Incorrect Default Permissions1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
45Planlayın | CVE-2022-36450İstismar yok | Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checkiobsidian · obsidian · CWE-20 | Kritik9,8 | — | %20,0 | 25 Tem 2022 |
39İzleyin | CVE-2021-38148İstismar yok | Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.obsidian · obsidian | Kritik9,8 | — | %1,2 | 6 Ağu 2021 |
32İzleyin | CVE-2023-33244İstismar yok | Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web pobsidian · obsidian | Yüksek8,2 | — | %0,5 | 20 May 2023 |
31İzleyin | CVE-2023-27035Kavram kanıtı | An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified obsidian · obsidian · CWE-276 | Yüksek7,5 | — | %1,8 | 1 May 2023 |
31İzleyin | CVE-2021-42057İstismar yok | Obsidian Dataview through 0.4.12-hotfix1 allows eval injection.obsidian · obsidian dataview · CWE-94 | Yüksek7,8 | — | %1,2 | 4 Kas 2021 |
28İzleyin | CVE-2023-2110İstismar yok | Obsidian Local File Disclosureobsidian · obsidian · CWE-22 | Yüksek7,1 | — | %0,4 | 19 Ağu 2023 |
- CVE-2022-3645045Planlayın
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checki
KritikCVSS 9,8İstismar yokEPSS %20obsidian · obsidian25 Tem 2022
- CVE-2021-3814839İzleyin
Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.
KritikCVSS 9,8İstismar yokEPSS %1obsidian · obsidian6 Ağu 2021
- CVE-2023-3324432İzleyin
Obsidian before 1.2.2 allows calls to unintended APIs (for microphone access, camera access, and desktop notification) via an embedded web p
YüksekCVSS 8,2İstismar yokEPSS %0obsidian · obsidian20 May 2023
- CVE-2023-2703531İzleyin
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified
YüksekCVSS 7,5Kavram kanıtıEPSS %2obsidian · obsidian1 May 2023
- CVE-2021-4205731İzleyin
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection.
YüksekCVSS 7,8İstismar yokEPSS %1obsidian · obsidian dataview4 Kas 2021
- CVE-2023-211028İzleyin
Obsidian Local File Disclosure
YüksekCVSS 7,1İstismar yokEPSS %0obsidian · obsidian19 Ağu 2023