Логотип exploitDog
bind:CVE-2020-4076
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-4076

Количество 3

Количество 3

nvd логотип

CVE-2020-4076

больше 5 лет назад

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using contextIsolation are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2020-4076

больше 5 лет назад

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a ...

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-m93v-9qjc-3g79

больше 5 лет назад

Context isolation bypass via leaked cross-context objects in Electron

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2020-4076

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using contextIsolation are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-4076

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a ...

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
github логотип
GHSA-m93v-9qjc-3g79

Context isolation bypass via leaked cross-context objects in Electron

CVSS3: 7.8
0%
Низкий
больше 5 лет назад

Уязвимостей на страницу