CVE-2021-21384

shescape is a simple shell escape package for JavaScript. In shescape before version 1.1.3, anyone using _Shescape_ to defend against shell injection may still be vulnerable against shell injection if the attacker manages to insert a into the payload. For an example see the referenced GitHub Security Advisory. The problem has been patched in version 1.1.3. No further changes are required.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:shescape_project:shescape:*:*:*:*:*:node.js:*:*
OR cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:opengroup:unix:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-03-19 00:15

Updated : 2024-02-28 18:08


NVD link : CVE-2021-21384

Mitre link : CVE-2021-21384

CVE.ORG link : CVE-2021-21384


JSON object : View

Products Affected

shescape_project

  • shescape

opengroup

  • unix

microsoft

  • windows
CWE
CWE-88

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')