Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WireDesktop affected by CVE-2018-1000136 - Electron nodeIntegration Bypass? #1467

Closed
tokariu opened this issue May 14, 2018 · 2 comments
Closed

Comments

@tokariu
Copy link

tokariu commented May 14, 2018

As this CVE got disclosed lately: https://www.trustwave.com/Resources/SpiderLabs-Blog/CVE-2018-1000136---Electron-nodeIntegration-Bypass/
i wonder if Wire too is affected like all the other electron based apps.

even though it's very comfortable due to it's portability, electron based apps seem to be a rather bad choice now when it comes to security - and shouldn't Wire take care about security in the first place? do we have alternatives?

@ij0n
Copy link

ij0n commented May 14, 2018

https://twitter.com/pwnsdx/status/996011703384100864 says that wire is not affected
the dev claims that this line:

event.preventDefault();
effectively stops the described attack vector.

for now I am inclined to believe this, but I would love to hear a more detailled response from wire

@raphaelrobert
Copy link

The code mentioned above prevents a new window from being opened, which was a pre-requisite for the vulnerability to be exploitable.

I will close the ticket, as Wire is not affected by this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants