CVE-2017-1000424

MEDIUM

Github Electron <1.6.11, <1.7.5 - Open Redirect

Title source: llm
STIX 2.1

Description

Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://github.com/electron/electron/pull/10008
Third Party Advisory x_refsource_confirm
https://github.com/electron/electron/pull/10008/files

Scores

CVSS v3 4.3
EPSS 0.0098
EPSS Percentile 58.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Details

Status published
Products (2)
atom/electron 1.6.4 - 1.6.11
npm/electron 1.7.0 - 1.7.6npm
Published Jan 02, 2018
Tracked Since Feb 18, 2026