CVE-2021-39184
Summary
| CVE | CVE-2021-39184 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-10-12 19:15:00 UTC |
| Updated | 2022-08-05 10:49:00 UTC |
| Description | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The thumbnail can potentially include significant parts of the original file, including textual data in many cases. Versions 15.0.0-alpha.10, 14.0.0, 13.3.0, 12.1.0, and 11.5.0 all contain a fix for the vulnerability. Two workarounds aside from upgrading are available. One may make the vulnerability significantly more difficult for an attacker to exploit by enabling `contextIsolation` in one's app. One may also disable the functionality of the `createThumbnailFromPath` API if one does not need it. |
Risk And Classification
Problem Types: CWE-862
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Electronjs | Electron | All | All | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta1 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta10 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta11 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta12 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta13 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta14 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta15 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta16 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta17 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta18 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta19 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta2 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta20 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta21 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta22 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta23 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta24 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta25 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta3 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta4 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta5 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta6 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta7 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta8 | All | All |
| Application | Electronjs | Electron | 14.0.0 | beta9 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha1 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha2 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha3 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha4 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha5 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha6 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha7 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha8 | All | All |
| Application | Electronjs | Electron | 15.0.0 | alpha9 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix: remove ipc wrapper for nativeImage.createThumbnailFromPath by nornagon · Pull Request #30728 · electron/electron · GitHub | MISC | github.com | |
| Sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API · Advisory · electron/electron · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980372 Nodejs (npm) Security Update for electron (GHSA-mpjm-v997-c4h4)