CVE-2018-15685
Last modified
CVE-2018-15685 is a vulnerability of currently unknown severity. GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.. EPSS estimates a 10.43% chance of exploitation in the next 30 days.
Description
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Electronjs | Electron | 1.7.15 | — |
| Electronjs | Electron | 1.8.7 | — |
| Electronjs | Electron | 2.0.7 | — |
| Electronjs | Electron | 3.0.0 | Beta6 |
References
- https://electronjs.org/blog/web-preferences-fixMitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/45272/Exploit, Third Party Advisory, VDB Entry
- https://electronjs.org/blog/web-preferences-fixMitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/45272/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-15685?
How severe is CVE-2018-15685?
How do I fix CVE-2018-15685?
Are you affected by CVE-2018-15685?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
