Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.
References
Link | Resource |
---|---|
https://electron.atom.io/blog/2017/09/27/chromium-rce-vulnerability-fix | Broken Link |
https://nodesecurity.io/advisories/539 | Third Party Advisory |
https://electron.atom.io/blog/2017/09/27/chromium-rce-vulnerability-fix | Broken Link |
https://nodesecurity.io/advisories/539 | Third Party Advisory |
Configurations
History
21 Nov 2024, 03:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://electron.atom.io/blog/2017/09/27/chromium-rce-vulnerability-fix - Broken Link | |
References | () https://nodesecurity.io/advisories/539 - Third Party Advisory |
Information
Published : 2018-06-07 02:29
Updated : 2024-11-21 03:15
NVD link : CVE-2017-16151
Mitre link : CVE-2017-16151
CVE.ORG link : CVE-2017-16151
JSON object : View
Products Affected
electronjs
- electron
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')