PT-2018-9296 · Github · Electron
Marshallofsound
·
Publicado
2018-03-07
·
Atualizado
2018-04-20
·
CVE-2018-1000118
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Github Electron versions 1.8.2-beta.4 and earlier
Description:
The issue is related to a Command Injection vulnerability in the Protocol Handler of Github Electron. This vulnerability can be exploited when a victim opens an Electron protocol handler in their browser, potentially allowing an attacker to execute commands. The vulnerability is due to an incomplete fix, specifically because the blacklist used was not case insensitive, allowing an attacker to potentially bypass it.
Recommendations:
For Github Electron versions 1.8.2-beta.4 and earlier, update to Electron 1.8.2-beta.5 or later to resolve the issue.
Correção
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Electron