CVE-2023-44402

Electron is an open source framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. This only impacts apps that have the `embeddedAsarIntegrityValidation` and `onlyLoadAppFromAsar` fuses enabled. Apps without these fuses enabled are not impacted. This issue is specific to macOS as these fuses are only currently supported on macOS. Specifically this issue can only be exploited if your app is launched from a filesystem the attacker has write access too. i.e. the ability to edit files inside the `.app` bundle on macOS which these fuses are supposed to protect against. There are no app side workarounds, you must update to a patched version of Electron.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha2:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha3:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha4:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha5:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha6:*:*:*:node.js:*:*

History

21 Nov 2024, 08:25

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.0
v2 : unknown
v3 : 6.1
References () https://github.com/electron/electron/pull/39788 - Issue Tracking () https://github.com/electron/electron/pull/39788 - Issue Tracking
References () https://github.com/electron/electron/security/advisories/GHSA-7m48-wc93-9g85 - Vendor Advisory () https://github.com/electron/electron/security/advisories/GHSA-7m48-wc93-9g85 - Vendor Advisory
References () https://www.electronjs.org/docs/latest/tutorial/fuses - Product () https://www.electronjs.org/docs/latest/tutorial/fuses - Product

06 Dec 2023, 20:34

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0
CPE cpe:2.3:a:electronjs:electron:27.0.0:alpha4:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha2:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha3:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha5:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:*:*:*:*:*:node.js:*:*
cpe:2.3:a:electronjs:electron:27.0.0:alpha6:*:*:*:node.js:*:*
First Time Electronjs
Electronjs electron
References () https://www.electronjs.org/docs/latest/tutorial/fuses - () https://www.electronjs.org/docs/latest/tutorial/fuses - Product
References () https://github.com/electron/electron/security/advisories/GHSA-7m48-wc93-9g85 - () https://github.com/electron/electron/security/advisories/GHSA-7m48-wc93-9g85 - Vendor Advisory
References () https://github.com/electron/electron/pull/39788 - () https://github.com/electron/electron/pull/39788 - Issue Tracking

01 Dec 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-01 22:15

Updated : 2024-11-21 08:25


NVD link : CVE-2023-44402

Mitre link : CVE-2023-44402

CVE.ORG link : CVE-2023-44402


JSON object : View

Products Affected

electronjs

  • electron
CWE
CWE-345

Insufficient Verification of Data Authenticity