shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell. This bug has been patched in version 1.7.4.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/ericcornelissen/shescape/commit/0b976dab645abf45ffd85e74a8c6e51ee2f42d63 - Patch | |
References | () https://github.com/ericcornelissen/shescape/pull/1142 - Patch | |
References | () https://github.com/ericcornelissen/shescape/releases/tag/v1.7.4 - Release Notes | |
References | () https://github.com/ericcornelissen/shescape/security/advisories/GHSA-j55r-787p-m549 - Exploit, Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
01 Sep 2023, 18:02
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://github.com/ericcornelissen/shescape/releases/tag/v1.7.4 - Release Notes | |
References | (MISC) https://github.com/ericcornelissen/shescape/security/advisories/GHSA-j55r-787p-m549 - Exploit, Patch, Vendor Advisory | |
References | (MISC) https://github.com/ericcornelissen/shescape/commit/0b976dab645abf45ffd85e74a8c6e51ee2f42d63 - Patch | |
References | (MISC) https://github.com/ericcornelissen/shescape/pull/1142 - Patch | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.6 |
CPE | cpe:2.3:a:shescape_project:shescape:*:*:*:*:*:node.js:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
First Time |
Shescape Project
Microsoft Shescape Project shescape Microsoft windows |
23 Aug 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-23 21:15
Updated : 2024-11-21 08:18
NVD link : CVE-2023-40185
Mitre link : CVE-2023-40185
CVE.ORG link : CVE-2023-40185
JSON object : View
Products Affected
microsoft
- windows
shescape_project
- shescape
CWE
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences