Arbitrary Code Injection

Affecting org.webjars.npm:electron artifact, versions (,1.4.15)

Report new vulnerabilities
Do your applications use this vulnerable package? Test your applications

Overview

electron is a framework for creating native applications with web technologies like JavaScript, HTML, and CSS. It takes care of the hard parts so you can focus on the core of your application.

Affected versions of the package are vulnerable to Arbitrary Code Injection. A malicious user can create a specially crafted site which will be loaded in the preload script and would run in the main JavaScript context.

Remediation

Upgrade electron to version 1.4.15 or higher.

References

CVSS Score

9.8
high severity
  • Attack Vector
    Network
  • Attack Complexity
    Low
  • Privileges Required
    None
  • User Interaction
    None
  • Scope
    Unchanged
  • Confidentiality
    High
  • Integrity
    High
  • Availability
    High
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Credit
Unknown
CWE
CWE-284
Snyk ID
SNYK-JAVA-ORGWEBJARSNPM-479664
Disclosed
04 Jan, 2017
Published
09 Oct, 2017