CVE-2021-38148: Critical severity Obsidian Obsidian vulnerability
Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/obsidianto a version that resolves this vulnerability.Fixed in 0.12.12
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-38148.
What is the severity of CVE-2021-38148?
The severity of CVE-2021-38148 is critical (9.8).
Which software versions are affected by CVE-2021-38148?
The Obsidian software versions before 0.12.12 are affected by CVE-2021-38148.
What is the impact of CVE-2021-38148?
CVE-2021-38148 allows an attacker to execute arbitrary code or perform other malicious actions by tricking a user into opening a non-http/https URL without requiring user confirmation.
Where can I find more information about CVE-2021-38148?
You can find more information about CVE-2021-38148 at the following link: [https://forum.obsidian.md/t/obsidian-release-v0-12-12/21564](https://forum.obsidian.md/t/obsidian-release-v0-12-12/21564)