PT-2024-23121 · Unknown · Electron Packager

Marshallofsound

·

Published

2024-03-29

·

Updated

2025-05-07

·

CVE-2024-29900

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Electron Packager versions prior to 18.3.1
Description A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory could contain sensitive information such as environment variables, secrets files, etc.
Recommendations For versions prior to 18.3.1, update to version 18.3.1 to resolve the issue. As a temporary workaround, consider avoiding the use of sensitive information in the application source code until the update is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-29900
GHSA-34H3-8MW4-QW57

Affected Products

Electron Packager