Логотип exploitDog
bind:CVE-2022-29281
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-29281

Количество 2

Количество 2

nvd логотип

CVE-2022-29281

почти 4 года назад

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-47xc-8r2q-5m83

почти 4 года назад

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-29281

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

CVSS3: 8.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-47xc-8r2q-5m83

Notable before 1.9.0-beta.8 doesn't effectively prevent the opening of executable files when clicking on a link. There is improper validation of the file URI scheme. A hyperlink to an SMB share could lead to execution of an arbitrary program (or theft of NTLM credentials via an SMB relay attack, because the application resolves UNC paths).

CVSS3: 8.8
1%
Низкий
почти 4 года назад

Уязвимостей на страницу