6.0 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
25 packages
- electron
- electron_39
- electron_40
- electron_41
- electron_42
- electron_43
- electron-bin
- electron-cash
- electron-mail
- electron-fiddle
- electron_39-bin
- electron_40-bin
- electron_41-bin
- electron_42-bin
- electron_43-bin
- todoist-electron
- jitsi-meet-electron
- electron-chromedriver
- idrisPackages.electron
- electron-chromedriver_38
- electron-chromedriver_39
- electron-chromedriver_40
- electron-chromedriver_41
- electron-chromedriver_42
- electron-chromedriver_43
- @LeSuisse dismissed
Electron: shell.openPath path validation bypass via embedded null byte
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject paths containing embedded null bytes. Apps that perform string-only validation of file paths, for example checking the file extension, before passing them to shell.openPath() could be bypassed, allowing an attacker-controlled path to open a different file than the one that passed validation. Apps are only affected if they pass paths derived from untrusted input to shell.openPath() and rely on string-based validation without a filesystem check. This issue is fixed in versions 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1.
References
-
https://github.com/electron/electron/security/advisories/GHSA-5c9j-mhmv-5xgx x_refsource_CONFIRM
Affected products
- ==>= 41.0.0-alpha.1, < 41.1.1
- ==>= 42.0.0-alpha.1, < 42.0.0-beta.1
- ==< 39.8.6
- ==>= 40.0.0-alpha.1, < 40.9.0
Matching in nixpkgs
Ignored packages (25)
pkgs.electron
Cross platform desktop application shell
pkgs.electron_39
Cross platform desktop application shell
pkgs.electron_40
Cross platform desktop application shell
pkgs.electron_41
Cross platform desktop application shell
pkgs.electron_42
Cross platform desktop application shell
pkgs.electron_43
Cross platform desktop application shell
pkgs.electron-bin
Cross platform desktop application shell
pkgs.electron-cash
Bitcoin Cash SPV Wallet
pkgs.electron-mail
Unofficial Election-based ProtonMail desktop client
pkgs.electron-fiddle
Easiest way to get started with Electron
pkgs.electron_39-bin
Cross platform desktop application shell
pkgs.electron_40-bin
Cross platform desktop application shell
pkgs.electron_41-bin
Cross platform desktop application shell
pkgs.electron_42-bin
Cross platform desktop application shell
pkgs.electron_43-bin
Cross platform desktop application shell
pkgs.todoist-electron
To-Do List App & Task Manager
pkgs.jitsi-meet-electron
Jitsi Meet desktop application powered by Electron
pkgs.electron-chromedriver
WebDriver server for running Selenium tests on Chrome
pkgs.idrisPackages.electron
Electron bindings for Idris
-
nixos-unstable 2016-03-07
- nixpkgs-unstable 2016-03-07
- nixos-unstable-small 2016-03-07
-
nixos-26.05 2016-03-07
- nixos-26.05-small 2016-03-07
- nixpkgs-26.05-darwin 2016-03-07
pkgs.electron-chromedriver_38
None
pkgs.electron-chromedriver_39
WebDriver server for running Selenium tests on Chrome
pkgs.electron-chromedriver_40
WebDriver server for running Selenium tests on Chrome
pkgs.electron-chromedriver_41
WebDriver server for running Selenium tests on Chrome
pkgs.electron-chromedriver_42
WebDriver server for running Selenium tests on Chrome
pkgs.electron-chromedriver_43
WebDriver server for running Selenium tests on Chrome