Electron subject to Exfiltration of hashed SMB credentials on Windows via file:// redirect
Published Nov 8, 2022
7.2
HIGHCVSS 3.1
EPSS 0.56%
Description
The Electron framework enables writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions prior to 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7, Electron is vulnerable to Exposure of Sensitive Information. When following a redirect, Electron delays a check for redirecting to file:// URLs from other schemes. The contents of the file is not available to the renderer following the redirect, but if the redirect target is a SMB URL such as `file://some.website.com/`, then in some cases, Windows will connect to that server and attempt NTLM authentication, which can include sending hashed credentials.This issue has been patched in versions: 21.0.0-beta.1, 20.0.1, 19.0.11, and 18.3.7. Users are recommended to upgrade to the latest stable version of Electron. If upgrading isn't possible, this issue can be addressed without upgrading by preventing redirects to file:// URLs in the `WebContents.on('will-redirect')` event, for all WebContents as a workaround.
Affected products
-
- Version < 18.3.7StatusaffectedConstraints-
- Version >= 19.0.0-beta.1, < 19.0.11StatusaffectedConstraints-
- Version >= 20.0.0-beta.1, < 20.0.1StatusaffectedConstraints-
- Version >= v21.0.0-nightly.20220526, < 21.0.0-beta.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- < 18.3.7
- ≥ 19.0.0 · < 19.0.11
- ≥ 20.0.0 · < 20.0.1
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
- 21.0.0
No data.
Red Hat A-MQ Online
electron
Not affected
Red Hat Application Interconnect 1.0
skupper-router
Not affected
Red Hat Data Grid 8
electron
Not affected
Red Hat Decision Manager 7
electron
Out of support scope
Red Hat Fuse 7
electron
Not affected
Red Hat Integration Camel K 1
electron
Not affected
Red Hat Integration Service Registry
electron
Not affected
Red Hat JBoss Data Grid 7
electron
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
electron
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
electron
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
electron
Not affected
Red Hat Process Automation 7
electron
Out of support scope
Red Hat Process Automation 7
org.optaweb.employeerostering-optaweb-employee-rostering
Out of support scope
Red Hat Single Sign-On 7
electron
Not affected
Red Hat build of Apicurio Registry 2
electron
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat A-MQ Online | electron | Not affected | n/a |
| Red Hat Application Interconnect 1.0 | skupper-router | Not affected | n/a |
| Red Hat Data Grid 8 | electron | Not affected | n/a |
| Red Hat Decision Manager 7 | electron | Out of support scope | n/a |
| Red Hat Fuse 7 | electron | Not affected | n/a |
| Red Hat Integration Camel K 1 | electron | Not affected | n/a |
| Red Hat Integration Service Registry | electron | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | electron | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | electron | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | electron | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | electron | Not affected | n/a |
| Red Hat Process Automation 7 | electron | Out of support scope | n/a |
| Red Hat Process Automation 7 | org.optaweb.employeerostering-optaweb-employee-rostering | Out of support scope | n/a |
| Red Hat Single Sign-On 7 | electron | Not affected | n/a |
| Red Hat build of Apicurio Registry 2 | electron | Not affected | n/a |
electron
npm
Introduced 0 Fixed 18.3.7electron
npm
Introduced 20.0.0-beta.1 Fixed 20.0.1electron
npm
Introduced 19.0.0-beta.1 Fixed 19.0.11
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electron | 0 | 18.3.7 |
| npm | electron | 20.0.0-beta.1 | 20.0.1 |
| npm | electron | 19.0.0-beta.1 | 19.0.11 |
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-36077 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2141029 Issue Tracking
- https://github.com/advisories/GHSA-p2jh-44qj-pf2v Advisory
- https://github.com/electron/electron/security/advisories/GHSA-p2jh-44qj-pf2v MitigationThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36077
- https://www.cve.org/CVERecord?id=CVE-2022-36077
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-36077 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2141029 | Issue Tracking | |
| https://github.com/advisories/GHSA-p2jh-44qj-pf2v | Advisory | |
| https://github.com/electron/electron/security/advisories/GHSA-p2jh-44qj-pf2v | MitigationThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-36077 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-36077 |
Change history (0)
No recorded changes yet.