6.6
CVE-2023-39956
- EPSS 0.56%
- Veröffentlicht 06.09.2023 21:15:13
- Zuletzt bearbeitet 21.11.2024 08:16:06
- Erkennungen
Electron: Out-of-package code execution when launched with arbitrary cwd
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted. Specifically this issue can only be exploited if the following conditions are met: 1. The app is launched with an attacker-controlled working directory and 2. The attacker has the ability to write files to that working directory. This makes the risk quite low, in fact normally issues of this kind are considered outside of our threat model as similar to Chromium we exclude Physically Local Attacks but given the ability for this issue to bypass certain protections like ASAR Integrity it is being treated with higher importance. This issue has been fixed in versions:`26.0.0-beta.13`, `25.4.1`, `24.7.1`, `23.3.13`, and `22.3.19`. There are no app side workarounds, users must update to a patched version of Electron.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Electronjs ≫ Electron SwPlatform node.js Version < 22.3.9
Electronjs ≫ Electron SwPlatform node.js Version >= 23.0.0 < 23.3.13
Electronjs ≫ Electron SwPlatform node.js Version >= 24.0.0 < 24.7.1
Electronjs ≫ Electron SwPlatform node.js Version >= 25.0.0 < 25.5.0
Electronjs ≫ Electron Version 26.0.0 Update alpha1 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update alpha2 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update alpha3 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update alpha4 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update alpha5 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update alpha6 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update alpha7 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update alpha8 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta1 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta10 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta11 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta12 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta2 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta3 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta4 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta5 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta6 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta7 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta8 SwPlatform node.js
Electronjs ≫ Electron Version 26.0.0 Update beta9 SwPlatform node.js
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.56% | 0.423 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.6 | 1.8 | 4.7 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L
|
| security-advisories@github.com | 6.1 | 1.3 | 4.7 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:L
|
CWE-94 Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
https://github.com/electron/electron/security/advisories/GHSA-7x97-j373-85x5