{"id":"GHSA-q43m-ffwr-rpcc","summary":"SSL Validation Defaults to False in electron-packager","details":"Affected versions of `electron-packager` configure the generated application to disable SSL certificate verification by default. \n\nThis could allow an attacker with a privileged network position to launch a Man In The Middle (MITM) attack on the install process, intercepting the step where electron-packager downloads Electron for supported target platforms and architectures, and replacing the valid download with a tampered malicious one.\n\nThis only affects users using the electron-packager CLI. The strict-ssl option defaults to true for the node.js API.\n\n\n## Recommendation\n\n1. Update to version 7.0.0 or later.\n2. Delete the `electron-download` cache folder, which is by default located at `~/.electron`.","aliases":["CVE-2016-10534"],"modified":"2023-11-08T03:58:11.086959Z","published":"2019-02-18T23:58:24Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-295"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:50:47Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-10534"},{"type":"WEB","url":"https://github.com/electron-userland/electron-packager/issues/333"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-q43m-ffwr-rpcc"},{"type":"WEB","url":"https://www.npmjs.com/advisories/104"}],"affected":[{"package":{"name":"electron-packager","ecosystem":"npm","purl":"pkg:npm/electron-packager"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.2.1"},{"fixed":"7.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/02/GHSA-q43m-ffwr-rpcc/GHSA-q43m-ffwr-rpcc.json"}}],"schema_version":"1.9.0"}