The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade electron to version 44.0.0-beta.6, 43.5.0, 42.10.0 or higher.
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.
Affected versions of this package are vulnerable to Protection Mechanism Failure via insufficient keying of sandboxed preload script code cache entries, allowing a renderer process serving untrusted content to supply a malicious code cache entry that is later served to a different-site document. Because preload code cache entries were not bound to the originating site, a compromised or malicious renderer could write a cache entry under a hash it controls, and that entry could be consumed by a preload script running in a different security origin, effectively escaping the sandbox boundary and achieving arbitrary code execution in the browser process context with elevated privileges.
Note: This is only exploitable if the app loads untrusted content.