Improper Restriction of Rendered UI Layers or Frames Affecting electron package, versions >=8.0.0-beta.0 <8.5.1 >=9.0.0-beta.0 <9.3.0 >=10.0.0-beta.0 <10.0.1 >=11.0.0-beta.0 <11.0.0-beta.1
Threat Intelligence
Exploit Maturity
Mature
EPSS
0.14% (51st
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-ELECTRON-1016273
- published 7 Oct 2020
- disclosed 6 Oct 2020
- credit Masato Kinugawa
Introduced: 6 Oct 2020
CVE-2020-15174 Open this link in a new tabHow to fix?
Upgrade electron
to version 8.5.1, 9.3.0, 10.0.1, 11.0.0-beta.1 or higher.
Overview
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.
Affected versions of this package are vulnerable to Improper Restriction of Rendered UI Layers or Frames. The will-navigate
event that apps use to prevent navigations to unexpected destinations can be bypassed when a sub-frame performs a top-frame navigation across sites.
References
CVSS Scores
version 3.1