CVE-2018-1000118
Dashboard / Vulnerabilities / CVE-2018-1000118
Summary:
Details: Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol handler in their browser. This vulnerability appears to have been fixed in Electron 1.8.2-beta.5. This issue is due to an incomplete fix for CVE-2018-1000006, specifically the black list used was not case insensitive allowing an attacker to potentially bypass it.
References: https://electronjs.org/releases#1.8.2-beta.5, https://github.com/electron/electron/commit/ce361a12e355f9e1e99c989f1ea056c9e502dbe7
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
Introduced- 0
Fixed -None
Affected versions
1.8.2-beta\.1
1.8.2-beta\.2
1.8.2-beta\.3
1.8.2-beta\.4
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
