Out-of-Bounds Affecting electron package, versions <27.3.10 >=28.0.0 <28.3.0
Threat Intelligence
EPSS
0.1% (42nd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-ELECTRON-6564965
- published 23 Apr 2024
- disclosed 4 Apr 2024
- credit Tao Yan, Edouard Bochin
Introduced: 4 Apr 2024
CVE-2024-3159 Open this link in a new tabHow to fix?
Upgrade electron
to version 27.3.10, 28.3.0 or higher.
Overview
electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS.
Affected versions of this package are vulnerable to Out-of-Bounds memory access in V8
component. This vulnerability allowed a remote attacker to perform arbitrary read/write via a crafted HTML page.
CVSS Scores
version 3.1