CVE-2024-23745: Command Injection
In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit the execution of the application, enabling the execution of arbitrary commands within the application's context. NOTE: the vendor's perspective is that this is simply an instance of CVE-2022-48505, cannot properly be categorized as a product-level vulnerability, and cannot have a product-level fix because it is about incorrect caching of file signatures on macOS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23745?
CVE-2024-23745 has a high severity rating due to its potential for arbitrary command execution.
How do I fix CVE-2024-23745?
To fix CVE-2024-23745, update Notion Web Clipper to the latest version available.
What is the Dirty NIB attack related to CVE-2024-23745?
The Dirty NIB attack involves manipulating .nib files to execute unauthorized commands within the application.
Which version of Notion Web Clipper is affected by CVE-2024-23745?
Only Notion Web Clipper version 1.0.3(7) is affected by CVE-2024-23745.
Can Gatekeeper prevent exploitation of CVE-2024-23745?
Gatekeeper may not prevent the execution of modified applications related to CVE-2024-23745 even if the .nib file is compromised.