Описание
Electron vulnerable to URL spoofing via PDFium
Electron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
Пакеты
Наименование
electron
npm
Затронутые версииВерсия исправления
>= 1.7.0, < 1.7.6
1.7.6
Связанные уязвимости
CVSS3: 4.3
nvd
около 8 лет назад
Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
CVSS3: 4.3
debian
около 8 лет назад
Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable ...