First published: Tue Feb 20 2024(Updated: )
electron-pdf version 20.0.0 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the HTML content entered by the user.
Credit: help@fluidattacks.com help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
npm/electron-pdf | <=20.0.0 | |
Electron | =20.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1648 is considered a critical vulnerability due to its potential to allow remote attackers to access arbitrary local files.
To fix CVE-2024-1648, upgrade to version 20.0.1 or later of the electron-pdf package, which includes proper validation of HTML content.
The implications of CVE-2024-1648 include unauthorized access to sensitive local files by external attackers.
Yes, CVE-2024-1648 affects all versions of electron-pdf up to and including version 20.0.0.
CVE-2024-1648 specifically affects the electron-pdf package version 20.0.0.