PT-2022-28281 · Unknown · Advanced Rest Client

Published

2022-03-03

·

Updated

2022-03-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Advanced Rest Client versions prior to 17.0.9
Description The issue allows scripts embedded in a link target to execute any logic that Advanced Rest Client has access to from the renderer process. This includes file system access, data store access which may contain sensitive information, and some additional processes that only Advanced Rest Client should have access to. This occurs when the end-user clicks on a response header that contains a link, causing the target to be opened in a new window with the default preload script loaded.
Recommendations For versions prior to 17.0.9, update to version 17.0.9 to resolve the issue. As a temporary workaround, do not click on any link in the response headers view.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-V3WR-67PX-44XG

Affected Products

Advanced Rest Client