Логотип exploitDog
bind:CVE-2025-55305
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-55305

Количество 5

Количество 5

redhat логотип

CVE-2025-55305

5 месяцев назад

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2025-55305

5 месяцев назад

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2025-55305

5 месяцев назад

Electron is a framework for writing cross-platform desktop application ...

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vmqv-hx8q-j7mg

5 месяцев назад

Electron has ASAR Integrity Bypass via resource modification

CVSS3: 6.1
EPSS: Низкий
fstec логотип

BDU:2025-12971

6 месяцев назад

Уязвимость функций embeddedAsarIntegrityValidation() и onlyLoadAppFromAsar() программной платформы для создания приложений Electron, позволяющая нарушителю получить несанкционированный доступ на чтение и изменение данных

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-55305

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
nvd логотип
CVE-2025-55305

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR Integrity Bypass via resource modification. This only impacts apps that have the embeddedAsarIntegrityValidation and onlyLoadAppFromAsar fuses enabled. Apps without these fuses enabled are not impacted. This issue is fixed in versions 35.7.5, 36.8.1, 37.3.1 and 38.0.0-beta.6.

CVSS3: 6.1
0%
Низкий
5 месяцев назад
debian логотип
CVE-2025-55305

Electron is a framework for writing cross-platform desktop application ...

CVSS3: 6.1
0%
Низкий
5 месяцев назад
github логотип
GHSA-vmqv-hx8q-j7mg

Electron has ASAR Integrity Bypass via resource modification

CVSS3: 6.1
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2025-12971

Уязвимость функций embeddedAsarIntegrityValidation() и onlyLoadAppFromAsar() программной платформы для создания приложений Electron, позволяющая нарушителю получить несанкционированный доступ на чтение и изменение данных

CVSS3: 6.1
0%
Низкий
6 месяцев назад

Уязвимостей на страницу