Do your applications use this vulnerable package?
Test your applications
Overview
electron
is a framework for creating native applications with web technologies like JavaScript, HTML, and CSS. It takes care of the hard parts so you can focus on the core of your application.
Affected versions of the package are vulnerable to Arbitrary Code Injection. A malicious user can create a specially crafted site which will be loaded in the preload
script and would run in the main JavaScript context.
Remediation
Upgrade electron
to version 1.4.15 or higher.
References
CVSS Score
9.8
high severity
-
Attack VectorNetwork
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionNone
-
ScopeUnchanged
-
ConfidentialityHigh
-
IntegrityHigh
-
AvailabilityHigh
- Credit
- Unknown
- CWE
- CWE-284
- Snyk ID
- npm:electron:20170105
- Disclosed
- 04 Jan, 2017
- Published
- 09 Oct, 2017