Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is vulnerable to this exploit, regardless of whether the [sandbox option](https://electron.atom.io/docs/api/sandbox-option) is enabled.
References
Link | Resource |
---|---|
https://nodesecurity.io/advisories/539 | Third Party Advisory |
https://electron.atom.io/blog/2017/09/27/chromium-rce-vulnerability-fix | Broken Link |
Configurations
Information
Published : 2018-06-06 19:29
Updated : 2019-10-09 16:24
NVD link : CVE-2017-16151
Mitre link : CVE-2017-16151
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
electronjs
- electron