CVE-2018-15685
Summary
| CVE | CVE-2018-15685 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-23 05:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Electron WebPreferences - Remote Code Execution - Multiple remote Exploit |
EXPLOIT-DB |
www.exploit-db.com |
Exploit, Third Party Advisory, VDB Entry |
| WebPreferences Vulnerability Fix | Electron Blog |
MISC |
electronjs.org |
Mitigation, Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981035 Nodejs (npm) Security Update for electron (GHSA-hv9c-qwqg-qj3v)