CVE-2020-4075

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/07/2020
Last modified:
13/07/2020

Description

In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, arbitrary local file read is possible by defining unsafe window options on a child window opened via window.open. As a workaround, ensure you are calling `event.preventDefault()` on all new-window events where the `url` or `options` is not something you expect. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:electronjs:electron:*:*:*:*:*:*:*:* 7.0.0 (including) 7.2.4 (excluding)
cpe:2.3:a:electronjs:electron:*:*:*:*:*:*:*:* 8.0.0 (including) 8.2.4 (excluding)
cpe:2.3:a:electronjs:electron:9.0.0:-:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta10:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta11:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta12:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta13:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta14:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta15:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta16:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta17:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta18:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta19:*:*:*:*:*:*
cpe:2.3:a:electronjs:electron:9.0.0:beta2:*:*:*:*:*:*