Логотип exploitDog
bind:CVE-2024-29900
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-29900

Количество 2

Количество 2

nvd логотип

CVE-2024-29900

почти 2 года назад

Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-34h3-8mw4-qw57

почти 2 года назад

@electron/packager's build process memory potentially leaked into final executable

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-29900

Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-34h3-8mw4-qw57

@electron/packager's build process memory potentially leaked into final executable

CVSS3: 7.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу