Vue-devtools: Github Security Alert for Electron version

Created on 19 Oct 2018  路  2Comments  路  Source: vuejs/vue-devtools

Version

5.0.0-beta.3

Browser and OS info

Electron

Steps to reproduce

I use dev-tools in another project and github alert reported because dev-tools use old version electron (1.7.11). Github recommend upgrade version from 1.8.2

Reports error:

https://nvd.nist.gov/vuln/detail/CVE-2018-15685

https://nvd.nist.gov/vuln/detail/CVE-2018-15685

What is expected?

Newer electron version without security issues

What is actually happening?

You are delivering and old buggie electron version

Most helpful comment

This is a critical _remote code execution_ security issue and should be addressed immediately.

All 2 comments

On one of our github repos there is a complain about this dependency, must update

This is a critical _remote code execution_ security issue and should be addressed immediately.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

topul picture topul  路  4Comments

gustojs picture gustojs  路  3Comments

matthewsunrise picture matthewsunrise  路  3Comments

sithuaung picture sithuaung  路  4Comments

pxwee5 picture pxwee5  路  3Comments