4.3

CVE-2023-35931

Exploit

Shescape potential environment variable exposure on Windows with CMD

Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.


Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Shescape ProjectShescape SwPlatformnode.js Version < 1.7.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.522
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
security-advisories@github.com 3.1 1.6 1.4
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-526 Cleartext Storage of Sensitive Information in an Environment Variable

The product uses an environment variable to store unencrypted sensitive information.

https://github.com/ericcornelissen/shescape/commit/d0fce70f987ac0d8331f93cb45d47e79436173ac
Patch
https://github.com/ericcornelissen/shescape/pull/982
Patch
https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1
Release Notes
https://github.com/ericcornelissen/shescape/security/advisories/GHSA-3g7p-8qhx-mc8r
Vendor Advisory
Exploit