HIGH
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute
Published Mar 7, 2018
8.8
HIGHCVSS 3.0
EPSS 2.40%
Description
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol handler in their browser. This vulnerability appears to have been fixed in Electron 1.8.2-beta.5. This issue is due to an incomplete fix for CVE-2018-1000006, specifically the black list used was not case insensitive allowing an attacker to potentially bypass it.
Affected products
No data.
OR
- ≤ 1.8.1
- 1.8.2
- 1.8.2
- 1.8.2
- 1.8.2
No data.
No Red Hat product state for this CVE.
electron
npm
Introduced 0 Fixed 1.8.2-beta5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electron | 0 | 1.8.2-beta5 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://electronjs.org/releases#1.8.2-beta.5 x_refsource_CONFIRMThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-0179 Advisory
- https://github.com/advisories/GHSA-fjqr-fx3f-g4rv Advisory
- https://github.com/electron/electron/commit/ce361a12e355f9e1e99c989f1ea056c9e502dbe7 x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000118
| Link | Providers | Tags |
|---|---|---|
| https://electronjs.org/releases#1.8.2-beta.5 | x_refsource_CONFIRMThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-0179 | Advisory | |
| https://github.com/advisories/GHSA-fjqr-fx3f-g4rv | Advisory | |
| https://github.com/electron/electron/commit/ce361a12e355f9e1e99c989f1ea056c9e502dbe7 | x_refsource_CONFIRMPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000118 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 7, 2018
Updated Sep 16, 2024
Reserved Mar 7, 2018
Link CVE-2018-1000118
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-0179 GHSA-FJQR-FX3F-G4RV Assigner mitre
Published Mar 7, 2018
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2018-0179