Логотип exploitDog
bind:CVE-2025-55305
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-55305

Количество 5

Количество 5

redhat логотип

CVE-2025-55305

3 месяца назад

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-55305

3 месяца назад

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2025-55305

3 месяца назад

Electron is a framework for writing cross-platform desktop application ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vmqv-hx8q-j7mg

4 месяца назад

Electron has ASAR Integrity Bypass via resource modification

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-12971

4 месяца назад

Уязвимость функций embeddedAsarIntegrityValidation() и onlyLoadAppFromAsar() программной платформы для создания приложений Electron, позволяющая нарушителю получить несанкционированный доступ на чтение и изменение данных

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-55305

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

CVSS3: 6.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2025-55305

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

CVSS3: 6.1
0%
Низкий
3 месяца назад
debian логотип
CVE-2025-55305

Electron is a framework for writing cross-platform desktop application ...

CVSS3: 6.1
0%
Низкий
3 месяца назад
github логотип
GHSA-vmqv-hx8q-j7mg

Electron has ASAR Integrity Bypass via resource modification

CVSS3: 6.1
0%
Низкий
4 месяца назад
fstec логотип
BDU:2025-12971

Уязвимость функций embeddedAsarIntegrityValidation() и onlyLoadAppFromAsar() программной платформы для создания приложений Electron, позволяющая нарушителю получить несанкционированный доступ на чтение и изменение данных

CVSS3: 6.1
0%
Низкий
4 месяца назад

Уязвимостей на страницу