CVE-2021-39184

Exposure of Resource to Wrong Sphere in npm/electron

Identifiers

CVE-2021-39184, GHSA-mpjm-v997-c4h4

Package Slug

npm/electron

Vulnerability

Exposure of Resource to Wrong Sphere

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability allows a sandboxed renderer to request a thumbnail image of an arbitrary file on the user's system. The thumbnail can potentially include significant parts of the original file, including textual data in many cases. all contain a fix for the vulnerability. Two workarounds aside from upgrading are available. One may make the vulnerability significantly more difficult for an attacker to exploit by enabling contextIsolation in one's app. One may also disable the functionality of the createThumbnailFromPath API if one does not need it.

Affected Versions

All versions starting from 10.1.0 before 11.5.0, all versions starting from 12.0.0 before 12.1.0, all versions starting from 13.0.0 before 13.3.0, all versions starting from 14.0.0 up to 15.0.0

Solution

Upgrade to versions 11.5.0, 12.1.0, 13.3.0, 15.1.0 or above.

Last Modified

2021-10-21

source