electron is vulnerable to Insufficient Policy Enforcement
43
Medium Risk
electron's embedded Chromium service worker static router does not consistently enforce Cross-Origin-Resource-Policy on cache-source responses. Crafted pages that drive static router cache lookups can read cross-origin data that should stay isolated. Pre-fix builds leak readable cross-origin bodies through the cache source. The backport enforces CORP requirements and rejects opaque responses for static router cache sources.
You are affected if you are using a version that falls within the vulnerable range and applications use service worker static routing.
electron is vulnerable to Insufficient Policy Enforcement in versions 40.0.0 - 40.10.2, 41.0.0 - 41.7.1 and 42.0.0 - 42.3.3.
Upgrade the electron library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant