The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade electron to version 44.0.0-beta.5, 43.4.1, 42.9.2, 41.10.6 or higher.
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.
Affected versions of this package are vulnerable to Origin Validation Error via the registerFileProtocol and registerHttpProtocol (URLPipeLoader) handlers in ElectronURLLoaderFactory, which fail to apply the opaque response tag to cross-origin mode=no-cors fetch requests. The file and http sinks build or forward their own response head, dropping the opaque tag computed in StartLoading, so the response is delivered as a basic, script-readable response instead of an opaque one. An attacker serving content through a registered custom protocol can read cross-origin responses that should be inaccessible to script.
Note: This is only exploitable if the application registers a custom file or HTTP protocol handler, serves it through one of those handlers, and loads untrusted content.