CVE-2020-15096
Summary
| CVE | CVE-2020-15096 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-07 00:15:00 UTC |
| Updated | 2020-07-10 19:49:00 UTC |
| Description | In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using "contextIsolation" are affected. There are no app-side workarounds, you must update your Electron version to be protected. This is fixed in versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Electronjs | Electron | All | All | All | All |
| Application | Electronjs | Electron | 9.0.0 | - | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta1 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta10 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta11 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta12 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta13 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta14 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta15 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta16 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta17 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta18 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta19 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta2 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta20 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta3 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta4 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta5 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta6 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta7 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta8 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta9 | All | All |
| Application | Electronjs | Electron | All | All | All | All |
| Application | Electronjs | Electron | 9.0.0 | - | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta1 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta10 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta11 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta12 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta13 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta14 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta15 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta16 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta17 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta18 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta19 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta2 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta20 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta3 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta4 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta5 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta6 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta7 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta8 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Stable Releases | Electron | MISC | www.electronjs.org | Release Notes, Vendor Advisory |
| Context isolation bypass via Promise.then bug in V8 · Advisory · electron/electron · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983184 Nodejs (npm) Security Update for electron (GHSA-6vrv-94jv-crrg)