CVE-2018-15685: High severity electron vulnerability
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15685?
The severity of CVE-2018-15685 is high with a CVSS score of 8.1.
How does CVE-2018-15685 affect GitHub Electron?
CVE-2018-15685 affects GitHub Electron versions 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6.
What is the vulnerability in GitHub Electron?
The vulnerability in GitHub Electron is a WebPreferences vulnerability that can be leveraged to perform remote code execution.
How can CVE-2018-15685 be exploited?
CVE-2018-15685 can be exploited by certain scenarios involving IFRAME elements and the "nativeWindowOpen: true" or "sandbox: true" options.
Is there a fix available for CVE-2018-15685?
Yes, a fix is available for CVE-2018-15685. Please refer to the references for more information.