Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37974
HistoryNov 10, 2022 - 8:47 a.m.

Improper Access Control

2022-11-1008:47:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
electron
improper access control
ntlm authentication
sensitive information leak
smb url
software

EPSS

0.001

Percentile

31.3%

Electron is vulnerable to improper access control. The vulnerability is caused by Electron responding with NTLM authentication, including hashed credentials. This sensitive information leak occurs when the redirect target uses an SMB URL type starting withfile://, as the library delays the check for redirecting to file:// URLs from other schemes.

EPSS

0.001

Percentile

31.3%