← Back

CVE-2021-39184

nvd nist
Published: Oct 12, 2021Modified: Nov 21, 2024

JSON object

Loading...
8.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 4.0
Source: NVD

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to 11.5.0, 12.1.0, and 13.3.0 allows a sandboxed renderer to request a "thumbnail" image of an arbitrary file on the user's system. The thumbnail can potentially include significant parts of the original file, including textual data in many cases. Versions 15.0.0-alpha.10, 14.0.0, 13.3.0, 12.1.0, and 11.5.0 all contain a fix for the vulnerability. Two workarounds aside from upgrading are available. One may make the vulnerability significantly more difficult for an attacker to exploit by enabling `contextIsolation` in one's app. One may also disable the functionality of the `createThumbnailFromPath` API if one does not need it.

Affected (37)

Products: Electronjs: Electron
1 product
Electron
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Electronjs
From 10.1.0 to 11.5.0
From 12.0.0 to 12.1.0
From 13.0.0 to 13.3.0
Version 14.0.0 beta10
Version 14.0.0 beta11
Version 14.0.0 beta12
Version 14.0.0 beta13
Version 14.0.0 beta14
Version 14.0.0 beta15
Version 14.0.0 beta16
Version 14.0.0 beta17
Version 14.0.0 beta18
Version 14.0.0 beta19
Version 14.0.0 beta1
Version 14.0.0 beta20
Version 14.0.0 beta21
Version 14.0.0 beta22
Version 14.0.0 beta23
Version 14.0.0 beta24
Version 14.0.0 beta25
Version 14.0.0 beta2
Version 14.0.0 beta3
Version 14.0.0 beta4
Version 14.0.0 beta5
Version 14.0.0 beta6
Version 14.0.0 beta7
Version 14.0.0 beta8
Version 14.0.0 beta9
Version 15.0.0 alpha1
Version 15.0.0 alpha2
Version 15.0.0 alpha3
Version 15.0.0 alpha4
Version 15.0.0 alpha5
Version 15.0.0 alpha6
Version 15.0.0 alpha7
Version 15.0.0 alpha8
Version 15.0.0 alpha9

References (4)

Source: security-advisories@github.com
Third Party Advisory
Source: security-advisories@github.com
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory

Timeline

No history available yet.