VDB
EN
MEDIUM 5.3

GHSA-v93f-fgjr-hjrj

Electron: window.open features string controls some window options considered privileged

빠른 조치

GHSA-v93f-fgjr-hjrj — electron: 아래 명령으로 수정 버전으로 올리세요.

npm install electron@39.8.8

상세

### Impact Some window options supplied by web content in the `window.open()` features string were applied to the new `BrowserWindow` without an allowlist. Untrusted content could set window options it should not control, including options that cause the main process to access attacker-chosen file or network paths.

Apps are only affected if untrusted content can call `window.open()` and the app does not override child window options via `setWindowOpenHandler`. Apps that deny `window.open()` for untrusted content, or set `overrideBrowserWindowOptions` explicitly, are not affected.

### Workarounds Return `{ action: 'deny' }` from `setWindowOpenHandler` for untrusted content, or supply `overrideBrowserWindowOptions` so every window option is set explicitly.

### Fixed Versions * `42.0.0-beta.3` * `41.2.1` * `40.9.0` * `39.8.8`

### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

npm / electron
최초 영향 버전: 0 수정 버전: 39.8.8
수정 npm install electron@39.8.8
npm / electron
최초 영향 버전: 40.0.0-alpha.1 수정 버전: 40.9.0
수정 npm install electron@40.9.0
npm / electron
최초 영향 버전: 41.0.0-alpha.1 수정 버전: 41.2.1
수정 npm install electron@41.2.1
npm / electron
최초 영향 버전: 42.0.0-alpha.1 수정 버전: 42.0.0-beta.3
수정 npm install electron@42.0.0-beta.3

참고