CVE-2018-15685 – electron
Package
Manager: npm
Name: electron
Vulnerable Version: >=1.7.0 <1.7.16 || >=1.8.0 <1.8.8 || >=2.0.0 <2.0.8 || >=3.0.0-beta.1 <3.0.0-beta.7
Severity
Level: High
CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.13253 pctl0.93901
Details
Electron webPreferences vulnerability can be used to perform remote code execution GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a webPreferences vulnerability that can be leveraged to perform remote code execution. More information to determine if you are impacted can be found on the [electron blog](https://electronjs.org/blog/web-preferences-fix). ## Recommendation Upgrade Electron to >=3.0.0-beta.7, >=2.0.8, >=1.8.8, or >=1.7.16.
Metadata
Created: 2018-08-23T19:12:08Z
Modified: 2022-08-02T18:03:09Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/08/GHSA-hv9c-qwqg-qj3v/GHSA-hv9c-qwqg-qj3v.json
CWE IDs: ["CWE-1188"]
Alternative ID: GHSA-hv9c-qwqg-qj3v
Finding: F014
Auto approve: 1