Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Context isolation bypass via Promise in Electron
Vulnerability Description
In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using "contextIsolation" are affected. There are no app-side workarounds, you must update your Electron version to be protected. This is fixed in versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Vulnerability Type
违背信任边界
Vulnerability Title
OpenJS Electron 安全漏洞
Vulnerability Description
OpenJS Electron是OpenJS基金会的一款用于桌面GUI应用程序开发的开源框架。 OpenJS Electron中的contextIsolation模块存在安全漏洞。攻击者可利用该漏洞执行权限操作。以下产品及版本受到影响:OpenJS Electron 6.1.1之前版本,7.2.4之前版本,8.2.4之前版本,9.0.0-beta21之前版本。
CVSS Information
N/A
Vulnerability Type
N/A