QID 983183
QID 983183: Nodejs (npm) Security Update for electron (GHSA-h9jc-284h-533g)
Security update has been released for electron to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Apps using both `contextIsolation` and `contextBridge` are affected.
This is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions.
Solution
Customers are advised to refer to GHSA-h9jc-284h-533g for updates pertaining to this vulnerability.Workaround:
There are no app-side workarounds, you must update your Electron version to be protected.
There are no app-side workarounds, you must update your Electron version to be protected.
Vendor References
- GHSA-h9jc-284h-533g -
github.com/advisories/GHSA-h9jc-284h-533g
CVEs related to QID 983183
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h9jc-284h-533g | electron |
|