Description
Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
Remediation
References
https://github.com/electron/electron/pull/10008
https://github.com/electron/electron/pull/10008/files
Related Vulnerabilities
CVE-2020-12265 Vulnerability in maven package org.webjars.npm:decompress
CVE-2019-0195 Vulnerability in maven package org.apache.tapestry:tapestry-core
CVE-2018-16484 Vulnerability in npm package m-server
CVE-2018-18893 Vulnerability in maven package com.hubspot.jinjava:jinjava
CVE-2019-16545 Vulnerability in maven package org.jenkins-ci.plugins:qmetry-for-jira-test-management