PT-2024-20053 · Notion · Notion Web Clipper

Published

2024-01-30

·

Updated

2024-08-01

·

CVE-2024-23745

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notion Web Clipper version 1.0.3(7)
Description The Notion Web Clipper is susceptible to the Dirty NIB attack, where .nib files can be manipulated to execute arbitrary commands. Even if a .nib file is modified within an application, Gatekeeper may still permit the execution of the application, allowing the execution of arbitrary commands within the application's context.
Recommendations For Notion Web Clipper version 1.0.3(7), consider disabling the execution of .nib files until a proper fix is available, as the vendor's perspective is that this issue is related to incorrect caching of file signatures on macOS. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-23745

Affected Products

Notion Web Clipper