CVE-2018-1000136
Summary
| CVE | CVE-2018-1000136 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-23 19:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | Electron version 1.7 up to 1.7.12; 1.8 up to 1.8.3 and 2.0.0 up to 2.0.0-beta.3 contains an improper handling of values vulnerability in Webviews that can result in remote code execution. This attack appear to be exploitable via an app which allows execution of 3rd party code AND disallows node integration AND has not specified if webview is enabled/disabled. This vulnerability appears to have been fixed in 1.7.13, 1.8.4, 2.0.0-beta.4. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Webview Vulnerability Fix | Electron Blog |
MISC |
www.electronjs.org |
Mitigation, Patch, Vendor Advisory |
| CVE-2018-1000136 - Electron nodeIntegration Bypass | SpiderLabs blog | Trustwave |
MISC |
www.trustwave.com |
Exploit, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982287 Nodejs (npm) Security Update for electron (GHSA-8xwg-wv7v-4vqp)