MEDIUM
Typora Local File Disclosure
Published Aug 19, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.49%
Description
Improper path handling in Typora before 1.7.0-dev on Windows and Linux allows a crafted webpage to access local files and exfiltrate them to remote web servers via "typora://app/typemark/". This vulnerability can be exploited if a user opens a malicious markdown file in Typora, or copies text from a malicious webpage and paste it into Typora.
Affected products
-
- Version 0StatusaffectedConstraints<1.7.0-dev
- Version
-
- Version 0StatusaffectedConstraints<1.7.0-dev
- Version
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34415 Advisory
- https://starlabs.sg/advisories/23/23-2971/ third-party-advisoryExploitMitigationThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34415 | Advisory | |
| https://starlabs.sg/advisories/23/23-2971/ | third-party-advisoryExploitMitigationThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner STAR_Labs
Published Aug 19, 2023
Updated Oct 7, 2024
Reserved May 30, 2023
Link CVE-2023-2971
CISA Vulnrichment
Updated Oct 7, 2024
ENISA EUVD
EUVD-2023-34415 Assigner STAR_Labs
Published Aug 19, 2023
Updated Oct 7, 2024
Exploited since n/a
Link EUVD-2023-34415