Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6vrv-94jv-crrg

Опубликовано: 07 июл. 2020
Источник: github
Github: Прошло ревью
CVSS3: 6.8

Описание

Context isolation bypass via Promise in Electron

Impact

Apps using contextIsolation are affected.

This is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions.

Workarounds

There are no app-side workarounds, you must update your Electron version to be protected.

Fixed Versions

  • 9.0.0-beta.21
  • 8.2.4
  • 7.2.4
  • 6.1.11

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

electron

npm
Затронутые версииВерсия исправления

< 6.1.11

6.1.11

Наименование

electron

npm
Затронутые версииВерсия исправления

>= 7.0.0, < 7.2.4

7.2.4

Наименование

electron

npm
Затронутые версииВерсия исправления

>= 8.0.0, < 8.2.4

8.2.4

EPSS

Процентиль: 47%
0.00237
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-501

Связанные уязвимости

CVSS3: 6.8
nvd
больше 5 лет назад

In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using "contextIsolation" are affected. There are no app-side workarounds, you must update your Electron version to be protected. This is fixed in versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21.

CVSS3: 6.8
debian
больше 5 лет назад

In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, the ...

EPSS

Процентиль: 47%
0.00237
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-501