CVE-2018-15685

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/08/2018
Last modified:
03/10/2019

Description

GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:electronjs:electron:1.7.15:*:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:1.8.7:*:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:3.0.0:beta6:*:*:*:*:*:*