VDB
EN
MEDIUM 6.6

GHSA-m55f-7gqj-fr98

Electron: Extension tab APIs operate across session boundaries

빠른 조치

GHSA-m55f-7gqj-fr98 — electron: 아래 명령으로 수정 버전으로 올리세요.

npm install electron@39.8.8

상세

### Impact Extension tab and scripting APIs were not scoped to the extension's own `session`. A malicious or compromised extension loaded into one session could navigate, script, and read from windows belonging to a different session.

Apps are only affected if they load Chrome extensions via `session.loadExtension` and rely on separate sessions to isolate that extension from other content. Apps that do not load extensions, or that use a single session, are not affected.

### Workarounds Only load extensions from sources you trust; do not rely on session separation alone to contain an extension.

### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8`

### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / electron
최초 영향 버전: 0 수정 버전: 39.8.8
수정 npm install electron@39.8.8
npm / electron
최초 영향 버전: 40.0.0-alpha.1 수정 버전: 40.9.0
수정 npm install electron@40.9.0
npm / electron
최초 영향 버전: 41.0.0-alpha.1 수정 버전: 41.2.1
수정 npm install electron@41.2.1
npm / electron
최초 영향 버전: 42.0.0-alpha.1 수정 버전: 42.0.0-beta.3
수정 npm install electron@42.0.0-beta.3

참고