An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.
References
Configurations
History
30 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://forum.obsidian.md/t/embedded-web-pages-in-obsidian-canvas-can-use-sensitive-web-apis-without-the-users-permission-grant/54509 - Exploit | |
References | () https://github.com/fivex3/CVE-2023-27035 - Exploit, Third Party Advisory | |
References | () https://forum.obsidian.md/t/obsidian-release-v1-1-14-insider-build/54595 - Release Notes |
06 May 2023, 03:14
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://forum.obsidian.md/t/embedded-web-pages-in-obsidian-canvas-can-use-sensitive-web-apis-without-the-users-permission-grant/54509 - Exploit | |
References | (MISC) https://github.com/fivex3/CVE-2023-27035 - Exploit, Third Party Advisory | |
References | (MISC) https://forum.obsidian.md/t/obsidian-release-v1-1-14-insider-build/54595 - Release Notes | |
First Time |
Obsidian obsidian
Obsidian |
|
CWE | CWE-276 | |
CPE | cpe:2.3:a:obsidian:obsidian:1.1.9:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
01 May 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-05-01 22:15
Updated : 2025-01-30 17:15
NVD link : CVE-2023-27035
Mitre link : CVE-2023-27035
JSON object : View
Products Affected
obsidian
- obsidian
CWE
CWE-276
Incorrect Default Permissions