CVE-2020-4076
Summary
| CVE | CVE-2020-4076 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-07-07 00:15:00 UTC |
| Updated | 2020-07-13 19:48:00 UTC |
| Description | In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using contextIsolation are affected. This is fixed in versions 9.0.0-beta.21, 8.2.4 and 7.2.4. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Electronjs | Electron | All | All | All | All |
| Application | Electronjs | Electron | 9.0.0 | - | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta1 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta10 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta11 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta12 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta13 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta14 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta15 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta16 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta17 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta18 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta19 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta2 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta20 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta3 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta4 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta5 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta6 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta7 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta8 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta9 | All | All |
| Application | Electronjs | Electron | All | All | All | All |
| Application | Electronjs | Electron | 9.0.0 | - | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta1 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta10 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta11 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta12 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta13 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta14 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta15 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta16 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta17 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta18 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta19 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta2 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta20 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta3 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta4 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta5 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta6 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta7 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta8 | All | All |
| Application | Electronjs | Electron | 9.0.0 | beta9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Stable Releases | Electron | MISC | www.electronjs.org | Release Notes, Vendor Advisory |
| Context isolation bypass via leaked cross-context objects · Advisory · electron/electron · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 983185 Nodejs (npm) Security Update for electron (GHSA-m93v-9qjc-3g79)