GHSA-mq8j-3h7h-p8g7

Suggest an improvement
Source
https://github.com/advisories/GHSA-mq8j-3h7h-p8g7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-mq8j-3h7h-p8g7/GHSA-mq8j-3h7h-p8g7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-mq8j-3h7h-p8g7
Aliases
Published
2022-06-16T23:14:33Z
Modified
2023-11-08T04:09:12Z
Severity
  • 2.2 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Compromised child renderer processes could obtain IPC access without nodeIntegrationInSubFrames being enabled
Details

Impact

This vulnerability allows a renderer with JS execution to obtain access to a new renderer process with nodeIntegrationInSubFrames enabled which in turn allows effective access to ipcRenderer.

Please note the misleadingly named nodeIntegrationInSubFrames option does not implicitly grant Node.js access rather it depends on the existing sandbox setting. If your application is sandboxed then nodeIntegrationInSubFrames just gives access to the sandboxed renderer APIs (which includes ipcRenderer).

If your application then additionally exposes IPC messages without IPC senderFrame validation that perform privileged actions or return confidential data this access to ipcRenderer can in turn compromise your application / user even with the sandbox enabled.

Patches

This has been patched and the following Electron versions contain the fix:

  • 18.0.0-beta.6
  • 17.2.0
  • 16.2.6
  • 15.5.5

Workarounds

Ensure that all IPC message handlers appropriately validate senderFrame as per our security tutorial here.

For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org.

Database specific
{
    "cwe_ids":  [
        "CWE-668"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-06-16T23:14:33Z",
    "nvd_published_at":  "2022-06-13T21:15:00Z",
    "severity":  "LOW"
}
References

Affected packages

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
15.5.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-mq8j-3h7h-p8g7/GHSA-mq8j-3h7h-p8g7.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
16.0.0
Fixed
16.2.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-mq8j-3h7h-p8g7/GHSA-mq8j-3h7h-p8g7.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
17.0.0
Fixed
17.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-mq8j-3h7h-p8g7/GHSA-mq8j-3h7h-p8g7.json"

npm / electron

Package

Affected ranges

Type
SEMVER
Events
Introduced
18.0.0-beta.1
Fixed
18.0.0-beta.6

Database specific

last_known_affected_version_range
"<= 18.0.0-beta.5"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/06/GHSA-mq8j-3h7h-p8g7/GHSA-mq8j-3h7h-p8g7.json"