Description
Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1669 | Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1. |
Github GHSA |
GHSA-3g7p-8qhx-mc8r | Shescape potential environment variable exposure on Windows with CMD |
References
History
Thu, 05 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-05T16:09:33.483Z
Reserved: 2023-06-20T14:02:45.593Z
Link: CVE-2023-35931
Updated: 2024-08-02T16:37:40.072Z
Status : Modified
Published: 2023-06-23T20:15:09.357
Modified: 2024-11-21T08:09:00.100
Link: CVE-2023-35931
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA