HIGH
electron: Improper handling of values in Webviews
Published Mar 23, 2018
8.1
HIGHCVSS 3.0
EPSS 5.08%
Description
Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4.
Affected products
No data.
OR
- ≥ 1.7.0 · ≤ 1.7.12
- > 1.8.0 · ≤ 1.8.3
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
- 2.0.0
No data.
JBoss Developer Studio 11
Electron
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Developer Studio 11 | Electron | Not affected | n/a |
electron
npm
Introduced 1.7.0 Fixed 1.7.13electron
npm
Introduced 1.8.0 Fixed 1.8.4electron
npm
Introduced 2.0.0-beta.1 Fixed 2.0.0-beta.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electron | 1.7.0 | 1.7.13 |
| npm | electron | 1.8.0 | 1.8.4 |
| npm | electron | 2.0.0-beta.1 | 2.0.0-beta.5 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (14)
- https://access.redhat.com/security/cve/CVE-2018-1000136 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1560094 Issue Tracking
- https://electronjs.org/blog/webview-fix
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-0178 Advisory
- https://github.com/advisories/GHSA-8xwg-wv7v-4vqp Advisory
- https://github.com/electron/electron/commit/1a48ee28276e6588dbf4e70e58d78e7bfdc57043
- https://github.com/electron/electron/pull/12271
- https://github.com/electron/electron/pull/12292
- https://github.com/electron/electron/pull/12294
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000136
- https://www.cve.org/CVERecord?id=CVE-2018-1000136
- https://www.electronjs.org/blog/webview-fix x_refsource_MISCMitigationPatchVendor Advisory
- https://www.npmjs.com/advisories/574
- https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-1000136---Electron-nodeIntegration-Bypass/ x_refsource_MISCExploitThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 23, 2018
Updated Aug 5, 2024
Reserved Mar 21, 2018
Link CVE-2018-1000136
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2018-0178 GHSA-8XWG-WV7V-4VQP Assigner mitre
Published Mar 23, 2018
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2018-0178