{"id":"GHSA-p2jh-44qj-pf2v","summary":"Exfiltration of hashed SMB credentials on Windows via file:// redirect","details":"### Impact\nWhen following a redirect, Electron delays a check for redirecting to file:// URLs from other schemes. The contents of the file is not available to the renderer following the redirect, but if the redirect target is a SMB URL such as `file://some.website.com/`, then in some cases, Windows will connect to that server and attempt NTLM authentication, which can include sending hashed credentials.\n\n### Patches\nThis issue has been fixed in all current stable versions of Electron. Specifically, these versions contain the fixes:\n\n- 21.0.0-beta.1\n- 20.0.1\n- 19.0.11\n- 18.3.7\n\nWe recommend all apps upgrade to the latest stable version of Electron.\n\n### Workarounds\nIf upgrading isn't possible, this issue can be addressed without upgrading by preventing redirects to file:// URLs in the `WebContents.on('will-redirect')` event, for all WebContents:\n\n```js\napp.on('web-contents-created', (e, webContents) =\u003e {\n  webContents.on('will-redirect', (e, url) =\u003e {\n    if (/^file:/.test(url)) e.preventDefault()\n  })\n})\n```\n\n### For more information\nIf you have any questions or comments about this advisory, email us at [security@electronjs.org](mailto:security@electronjs.org).\n\n### Credit\nThanks to user @coolcoolnoworries for reporting this issue.","aliases":["CVE-2022-36077"],"modified":"2023-11-08T04:09:59.820649Z","published":"2022-11-10T12:38:57Z","database_specific":{"cwe_ids":["CWE-200","CWE-522"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-10T12:38:57Z","nvd_published_at":"2022-11-08T07:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/electron/electron/security/advisories/GHSA-p2jh-44qj-pf2v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-36077"},{"type":"PACKAGE","url":"https://github.com/electron/electron"}],"affected":[{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"18.3.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-p2jh-44qj-pf2v/GHSA-p2jh-44qj-pf2v.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"20.0.0-beta.1"},{"fixed":"20.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-p2jh-44qj-pf2v/GHSA-p2jh-44qj-pf2v.json"}},{"package":{"name":"electron","ecosystem":"npm","purl":"pkg:npm/electron"},"ranges":[{"type":"SEMVER","events":[{"introduced":"19.0.0-beta.1"},{"fixed":"19.0.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-p2jh-44qj-pf2v/GHSA-p2jh-44qj-pf2v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L"}]}