GHSA-v64r-4m7r-3mvq
Electron: HTTP redirect followed into local file loader
Quick fix
GHSA-v64r-4m7r-3mvq — electron: upgrade to the fixed version with the command below.
npm install electron@39.8.8 Details
### Impact When following HTTP redirects, `net.fetch()` and `net.request()` did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed.
Apps are only affected if they make `net` requests to attacker-influenced URLs with redirects followed (the default) and expose the response body. Apps that only request fixed, trusted URLs are not affected.
### Workarounds Set `redirect: 'error'` or `redirect: 'manual'` on requests to untrusted URLs and validate any redirect target before following it.
### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8`
### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)
Are you affected?
Enter the version of the package you're using.
Affected packages
42.0.0-alpha.1 Fixed in: 42.0.0-beta.3 npm install electron@42.0.0-beta.3