CVE-2021-39184, GHSA-mpjm-v997-c4h4
npm/electron
Exposure of Resource to Wrong Sphere
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability allows a sandboxed renderer to request a thumbnail
image of an arbitrary file on the user's system. The thumbnail can potentially include significant parts of the original file, including textual data in many cases. all contain a fix for the vulnerability. Two workarounds aside from upgrading are available. One may make the vulnerability significantly more difficult for an attacker to exploit by enabling contextIsolation
in one's app. One may also disable the functionality of the createThumbnailFromPath
API if one does not need it.
All versions starting from 10.1.0 before 11.5.0, all versions starting from 12.0.0 before 12.1.0, all versions starting from 13.0.0 before 13.3.0, all versions starting from 14.0.0 up to 15.0.0
Upgrade to versions 11.5.0, 12.1.0, 13.3.0, 15.1.0 or above.
2021-10-21
source |