PT-2018-9296 · Github · Electron

Marshallofsound

·

Published

2018-03-07

·

Updated

2018-04-20

·

CVE-2018-1000118

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Github Electron versions 1.8.2-beta.4 and earlier
Description: The issue is related to a Command Injection vulnerability in the Protocol Handler of Github Electron. This vulnerability can be exploited when a victim opens an Electron protocol handler in their browser, potentially allowing an attacker to execute commands. The vulnerability is due to an incomplete fix, specifically because the blacklist used was not case insensitive, allowing an attacker to potentially bypass it.
Recommendations: For Github Electron versions 1.8.2-beta.4 and earlier, update to Electron 1.8.2-beta.5 or later to resolve the issue.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000118
GHSA-FJQR-FX3F-G4RV

Affected Products

Electron