CVE-2023-23623 PUBLISHED CVSS 7.5 HIGH

Electron's Content-Secrity-Policy disabling eval not applied consistently in renderers with sandbox disabled

EPSS 0.50% · 65.8th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.50%
65.8th percentile

Affected Products

VendorProductVersions
electronelectron>= 22.0.0-beta.1, < 22.0.1, >= 23.0.0-alpha.1, < 23.0.0-alpha.2, >= 22.0.0-beta.1, < 22.0.1
npmelectron23.0.0-alpha.1, 22.0.0-beta.1, 23.0.0-alpha.1
atomelectron22.0.0_beta.1, 23.0.0_alpha.1, 22.0.0_beta.1
electronjselectron22.0.0, 22.0.0, 22.0.0

Timeline

References

Open in Interactive Console →