VDB
KO
HIGH 7.4

GHSA-v3j7-r9gq-3gjw

Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

Quick fix

GHSA-v3j7-r9gq-3gjw — electron: upgrade to the fixed version with the command below.

npm install electron@42.0.0

Details

### Impact A custom scheme registered with `supportFetchAPI: true` but without `corsEnabled: true` was not subject to CORS enforcement. A page loaded from a remote origin could therefore `fetch()` or `XMLHttpRequest` that scheme cross-origin and read the full response body, rather than the read being blocked.

Apps that serve sensitive data from such a scheme and load remote or untrusted content in a renderer are affected. Apps that set `corsEnabled: true`, or that do not load untrusted content, are not affected.

### Workarounds Set `corsEnabled: true` on schemes that must enforce CORS, and validate the request `Origin` in your protocol handler before returning sensitive data.

### Fixed Versions * `42.0.0` * `41.4.0` * `40.9.3` * `39.8.10`

### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 42.0.0-alpha.1 Fixed in: 42.0.0
Fix npm install electron@42.0.0
npm / electron
Introduced in: 41.0.0-alpha.1 Fixed in: 41.4.0
Fix npm install electron@41.4.0
npm / electron
Introduced in: 40.0.0-alpha.1 Fixed in: 40.9.3
Fix npm install electron@40.9.3
npm / electron
Introduced in: 0 Fixed in: 39.8.10
Fix npm install electron@39.8.10

References