CVE-2017-1000424: Medium severity Atom Electron vulnerability
Electron version 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
Other sources
Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000424?
CVE-2017-1000424 is considered a moderate severity vulnerability due to the risk of URL Spoofing when opening PDFs.
How do I fix CVE-2017-1000424?
To remediate CVE-2017-1000424, upgrade Electron to version 1.7.6 or later.
Which versions of Electron are affected by CVE-2017-1000424?
CVE-2017-1000424 affects Electron versions 1.7.0 to 1.7.5 and 1.6.4 to 1.6.11.
What type of attack is enabled by CVE-2017-1000424?
CVE-2017-1000424 enables a URL Spoofing attack that may allow a hacker to control the loading of arbitrary PDFs.
Can CVE-2017-1000424 impact my application using Electron?
Yes, if your application uses the affected versions of Electron, it is susceptible to CVE-2017-1000424.