← Back

CVE-2022-29257

nvd nist
Published: Jun 13, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: NVD

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components. This kind of attack would require significant privileges in a potential victim's own auto updating infrastructure and the ease of that attack entirely depends on the potential victim's infrastructure security. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. There are no known workarounds.

Affected (26)

Products: Electronjs: Electron
1 product
Electron
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Electronjs
Before 15.5.0
From 16.0.1 to 16.2.0
From 17.0.1 to 17.2.0
Version 16.0.0 beta1
Version 16.0.0 beta2
Version 16.0.0 beta3
Version 16.0.0 beta4
Version 16.0.0 beta5
Version 16.0.0 beta6
Version 16.0.0 beta7
Version 16.0.0 beta8
Version 16.0.0 beta9
Version 17.0.0 beta1
Version 17.0.0 beta2
Version 17.0.0 beta3
Version 17.0.0 beta4
Version 17.0.0 beta5
Version 17.0.0 beta6
Version 17.0.0 beta7
Version 17.0.0 beta8
Version 17.0.0 beta9
Version 18.0.0 beta1
Version 18.0.0 beta2
Version 18.0.0 beta3
Version 18.0.0 beta4
Version 18.0.0 beta5

References (2)

Source: security-advisories@github.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.