CVE-2022-36450: Input Validation
Published Jul 25, 2022
·Updated
Obsidian 0.14.x and 0.15.x before 0.15.5 allows obsidian://hook-get-address remote code execution because window.open is used without checking the URL.
Affected Software
1 affected component
Obsidian Obsidian>=0.14.0<0.15.5
Event History
Jul 25, 2022
CVE Published
via MITRE·06:15 AM
Data Sourced
via MITRE·06:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-36450.
2
What is the severity of CVE-2022-36450?
The severity of CVE-2022-36450 is critical with a CVSS score of 9.8.
3
What is the affected software for CVE-2022-36450?
The affected software for CVE-2022-36450 is Obsidian versions 0.14.x and 0.15.x before 0.15.5.
4
How does CVE-2022-36450 allow remote code execution?
CVE-2022-36450 allows remote code execution through the obsidian://hook-get-address URI scheme by using window.open without URL checking.
5
Is there a fix available for CVE-2022-36450?
Yes, the fix for CVE-2022-36450 is to update Obsidian to version 0.15.5 or later.