GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hv9c-qwqg-qj3v | Electron webPreferences vulnerability can be used to perform remote code execution |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T10:01:54.447Z
Reserved: 2018-08-21T00:00:00
Link: CVE-2018-15685
No data.
Status : Modified
Published: 2018-08-23T05:29:00.227
Modified: 2024-11-21T03:51:16.493
Link: CVE-2018-15685
No data.
OpenCVE Enrichment
No data.
Github GHSA