← Back

CVE-2022-21718

nvd nist
Published: Mar 22, 2022Modified: Nov 21, 2024

JSON object

Loading...
5.0
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Exploitability: 3.1 / Impact: 1.4
Source: NVD

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth API if the app has not configured a custom `select-bluetooth-device` event handler. This has been patched and Electron versions `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` contain the fix. Code from the GitHub Security Advisory can be added to the app to work around the issue.

Affected (9)

Products: Electronjs: Electron
1 product
Electron
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Electronjs
Before 13.6.6
From 14.0.0 to 14.2.4
From 15.0.0 to 15.3.5
From 16.0.0 to 16.0.6
Version 17.0.0 alpha1
Version 17.0.0 alpha2
Version 17.0.0 alpha3
Version 17.0.0 alpha4
Version 17.0.0 alpha5

References (6)

Source: security-advisories@github.com
Issue TrackingPatchThird Party Advisory
Source: security-advisories@github.com
Issue TrackingPatchThird Party Advisory
Source: security-advisories@github.com
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory

Timeline

No history available yet.