GHSA-34h3-8mw4-qw57

    Dashboard / Vulnerabilities / GHSA-34h3-8mw4-qw57

    GHSA-34h3-8mw4-qw57

    Published: 29 Mar 2024Last Modified: 10 Sept 2026

    Summary: @electron/packager's build process memory potentially leaked into final executable

    Details: ### Impact A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. ### Patches This issue is patched in 18.3.1 ### Workarounds No workarounds, please update to a patched version of `@electron/packager` immediately if impacated.

    Affected packages

    Package

    Name: @electron/packager

    Purl: pkg:npm/%40electron/packager

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 18.3.0
    Fixed -18.3.1

    Affected versions

    18.3.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-34h3-8mw4-qw57 | CVE-DB