PT-2024-20053 · Notion · Notion Web Clipper
Published
2024-01-30
·
Updated
2024-08-01
·
CVE-2024-23745
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Notion Web Clipper version 1.0.3(7)
Description
The Notion Web Clipper is susceptible to the Dirty NIB attack, where .nib files can be manipulated to execute arbitrary commands. Even if a .nib file is modified within an application, Gatekeeper may still permit the execution of the application, allowing the execution of arbitrary commands within the application's context.
Recommendations
For Notion Web Clipper version 1.0.3(7), consider disabling the execution of .nib files until a proper fix is available, as the vendor's perspective is that this issue is related to incorrect caching of file signatures on macOS. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notion Web Clipper