CVE-2024-23745: Command Injection

Published Jan 31, 2024
·
Updated

In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit the execution of the application, enabling the execution of arbitrary commands within the application's context. NOTE: the vendor's perspective is that this is simply an instance of CVE-2022-48505, cannot properly be categorized as a product-level vulnerability, and cannot have a product-level fix because it is about incorrect caching of file signatures on macOS.

Affected Software

1 affected component
Notion Web Clipper=1.0.3\(7\)

Event History

Jan 31, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-23745?

CVE-2024-23745 has a high severity rating due to its potential for arbitrary command execution.

2

How do I fix CVE-2024-23745?

To fix CVE-2024-23745, update Notion Web Clipper to the latest version available.

3

What is the Dirty NIB attack related to CVE-2024-23745?

The Dirty NIB attack involves manipulating .nib files to execute unauthorized commands within the application.

4

Which version of Notion Web Clipper is affected by CVE-2024-23745?

Only Notion Web Clipper version 1.0.3(7) is affected by CVE-2024-23745.

5

Can Gatekeeper prevent exploitation of CVE-2024-23745?

Gatekeeper may not prevent the execution of modified applications related to CVE-2024-23745 even if the .nib file is compromised.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203