CVE-2023-23623
Last modified
CVE-2023-23623 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that directive, is not respected in renderers that have sandbox disabled. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. A Content-Security-Policy that disables eval, specifically setting a `script-src` directive and _not_ providing `unsafe-eval` in that directive, is not respected in renderers that have sandbox disabled. i.e. `sandbox: false` in the `webPreferences` object. This allows usage of methods like `eval()` and `new Function` unexpectedly which can result in an expanded attack surface. This issue only ever affected the 22 and 23 major versions of Electron and has been fixed in the latest versions of those release lines. Specifically, these versions contain the fixes: 22.0.1 and 23.0.0-alpha.2 We recommend all apps upgrade to the latest stable version of Electron. If upgrading isn't possible, this issue can be addressed without upgrading by enabling `sandbox: true` on all renderers.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Electronjs | Electron | 22.0.0 | — |
| Electronjs | Electron | 23.0.0 | Alpha1 |
References
- https://github.com/electron/electron/security/advisories/GHSA-gxh7-wv9q-fwfrMitigation, Vendor Advisory
- https://github.com/electron/electron/security/advisories/GHSA-gxh7-wv9q-fwfrMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-23623?
How severe is CVE-2023-23623?
How do I fix CVE-2023-23623?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-23618Git for Windows is the Windows port of the revision control …7.8
- CVE-2023-23619Modelina is a library for generating data models based on in…8.8
- CVE-2023-2362The Float menu WordPress plugin before 5.0.2, Bubble Menu Wo…6.1
- CVE-2023-23620Discourse is an open-source discussion platform. Prior to ve…5.3
- CVE-2023-23621Discourse is an open-source discussion platform. Prior to ve…7.5
- CVE-2023-23622Discourse is an open-source discussion platform. Prior to ve…4.3
- CVE-2023-23624Discourse is an open-source discussion platform. Prior to ve…5.3
- CVE-2023-23625go-unixfs is an implementation of a unix-like filesystem on …7.5
- CVE-2023-23626go-bitfield is a simple bitfield package for the go language…7.5
- CVE-2023-23627Sanitize is an allowlist-based HTML and CSS sanitizer. Versi…6.1
- CVE-2023-23628Metabase is an open source data analytics platform. Affected…4.1
- CVE-2023-23629Metabase is an open source data analytics platform. Affected…6.3
Are you affected by CVE-2023-23623?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
