9.8

CVE-2022-29247

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with `nodeIntegrationInSubFrames` enabled which in turn allows effective access to `ipcRenderer`. The `nodeIntegrationInSubFrames` option does not implicitly grant Node.js access. Rather, it depends on the existing sandbox setting. If an application is sandboxed, then `nodeIntegrationInSubFrames` just gives access to the sandboxed renderer APIs, which include `ipcRenderer`. If the application then additionally exposes IPC messages without IPC `senderFrame` validation that perform privileged actions or return confidential data this access to `ipcRenderer` can in turn compromise your application / user even with the sandbox enabled. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. As a workaround, ensure that all IPC message handlers appropriately validate `senderFrame`.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ElectronjsElectron Version < 15.5.5
ElectronjsElectron Version >= 16.0.1 < 16.2.6
ElectronjsElectron Version >= 17.0.1 < 17.2.0
ElectronjsElectron Version16.0.0 Updatebeta1
ElectronjsElectron Version16.0.0 Updatebeta2
ElectronjsElectron Version16.0.0 Updatebeta3
ElectronjsElectron Version16.0.0 Updatebeta4
ElectronjsElectron Version16.0.0 Updatebeta5
ElectronjsElectron Version16.0.0 Updatebeta6
ElectronjsElectron Version16.0.0 Updatebeta7
ElectronjsElectron Version16.0.0 Updatebeta8
ElectronjsElectron Version16.0.0 Updatebeta9
ElectronjsElectron Version17.0.0 Updatebeta1
ElectronjsElectron Version17.0.0 Updatebeta2
ElectronjsElectron Version17.0.0 Updatebeta3
ElectronjsElectron Version17.0.0 Updatebeta4
ElectronjsElectron Version17.0.0 Updatebeta5
ElectronjsElectron Version17.0.0 Updatebeta6
ElectronjsElectron Version17.0.0 Updatebeta7
ElectronjsElectron Version17.0.0 Updatebeta8
ElectronjsElectron Version17.0.0 Updatebeta9
ElectronjsElectron Version18.0.0 Updatebeta1
ElectronjsElectron Version18.0.0 Updatebeta2
ElectronjsElectron Version18.0.0 Updatebeta3
ElectronjsElectron Version18.0.0 Updatebeta4
ElectronjsElectron Version18.0.0 Updatebeta5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.8% 0.735
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
security-advisories@github.com 2.2 0.7 1.4
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.