VDB
EN
MEDIUM 5.4

GHSA-hvf8-h2qh-37m9

IPC messages delivered to the wrong frame in Electron

상세

### Impact IPC messages sent from the main process to a subframe in the renderer process, through `webContents.sendToFrame`, `event.reply` or when using the `remote` module, can in some cases be delivered to the wrong frame.

If your app does ANY of the following, then it is impacted by this issue: - Uses `remote` - Calls `webContents.sendToFrame` - Calls `event.reply` in an IPC message handler

### Patches This has been fixed in the following versions:

- 9.4.0 - 10.2.0 - 11.1.0 - 12.0.0-beta.9

### Workarounds There are no workarounds for this issue.

### For more information If you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org).

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / electron
최초 영향 버전: 0 수정 버전: 9.4.0
수정 npm install electron@9.4.0
npm / electron
최초 영향 버전: 10.0.0 수정 버전: 10.2.0
수정 npm install electron@10.2.0
npm / electron
최초 영향 버전: 11.0.0 수정 버전: 11.1.0
수정 npm install electron@11.1.0

참고