Execution with Unnecessary Privileges Affecting @advanced-rest-client/base package, versions <0.1.10


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-ADVANCEDRESTCLIENTBASE-2420033
  • published9 Mar 2022
  • disclosed3 Mar 2022
  • creditUnknown

Introduced: 3 Mar 2022

CVE NOT AVAILABLE CWE-250  (opens in a new tab)

How to fix?

Upgrade @advanced-rest-client/base to version 0.1.10 or higher.

Overview

Affected versions of this package are vulnerable to Execution with Unnecessary Privileges when the end-user click on the response header that contains a link the target will be opened in ARC new window which will preload the script and allow it to execute any logic that ARC has access to from the renderer process. It includes file system access, data store access, and some additional processes that only ARC should have access to.

References

CVSS Scores

version 3.1