GHSA-q43m-ffwr-rpcc

    Dashboard / Vulnerabilities / GHSA-q43m-ffwr-rpcc

    GHSA-q43m-ffwr-rpcc

    Published: 18 Feb 2019Last Modified: 8 Nov 2023

    Summary: SSL Validation Defaults to False in electron-packager

    Details: Affected versions of `electron-packager` configure the generated application to disable SSL certificate verification by default. This could allow an attacker with a privileged network position to launch a Man In The Middle (MITM) attack on the install process, intercepting the step where electron-packager downloads Electron for supported target platforms and architectures, and replacing the valid download with a tampered malicious one. This only affects users using the electron-packager CLI. The strict-ssl option defaults to true for the node.js API. ## Recommendation 1. Update to version 7.0.0 or later. 2. Delete the `electron-download` cache folder, which is by default located at `~/.electron`.

    Affected packages

    Package

    Name: electron-packager

    Purl: pkg:npm/electron-packager

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 5.2.1
    Fixed -7.0.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High