icon

We found results for “

CVE-2024-29900

Good to know:

icon
icon

Date: March 29, 2024

Electron Packager bundles Electron-based application source code with a renamed Electron executable and supporting files into folders ready for distribution. A random segment of ~1-10kb of Node.js heap memory allocated either side of a known buffer will be leaked into the final executable. This memory _could_ contain sensitive information such as environment variables, secrets files, etc. This issue is patched in 18.3.1.

Language: TYPE_SCRIPT

Severity Score

Severity Score

Weakness Type (CWE)

Transmission of Private Resources into a New Sphere ('Resource Leak')

CWE-402

Top Fix

icon

Upgrade Version

Upgrade to version @electron/packager - 18.3.1

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us