VDB
KO
MEDIUM 5.9

GHSA-v64r-4m7r-3mvq

Electron: HTTP redirect followed into local file loader

Quick fix

GHSA-v64r-4m7r-3mvq — electron: upgrade to the fixed version with the command below.

npm install electron@39.8.8

Details

### Impact When following HTTP redirects, `net.fetch()` and `net.request()` did not restrict which schemes a redirect could target. A remote server could redirect a request to a local resource, and if the app returns or forwards the response body, local file contents could be disclosed.

Apps are only affected if they make `net` requests to attacker-influenced URLs with redirects followed (the default) and expose the response body. Apps that only request fixed, trusted URLs are not affected.

### Workarounds Set `redirect: 'error'` or `redirect: 'manual'` on requests to untrusted URLs and validate any redirect target before following it.

### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8`

### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 0 Fixed in: 39.8.8
Fix npm install electron@39.8.8
npm / electron
Introduced in: 40.0.0-alpha.1 Fixed in: 40.9.1
Fix npm install electron@40.9.1
npm / electron
Introduced in: 41.0.0-alpha.1 Fixed in: 41.2.1
Fix npm install electron@41.2.1
npm / electron
Introduced in: 42.0.0-alpha.1 Fixed in: 42.0.0-beta.3
Fix npm install electron@42.0.0-beta.3

References