Description
Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.
Remediation
References
https://github.com/ericcornelissen/shescape/commit/d0fce70f987ac0d8331f93cb45d47e79436173ac
https://github.com/ericcornelissen/shescape/pull/982
https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1
https://github.com/ericcornelissen/shescape/security/advisories/GHSA-3g7p-8qhx-mc8r
Related Vulnerabilities
CVE-2024-4367 Vulnerability in maven package org.webjars.bowergithub.mozilla:pdfjs-dist
CVE-2022-23617 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-26183 Vulnerability in npm package pnpm
CVE-2023-37953 Vulnerability in maven package com.mabl.integration.jenkins:mabl-integration
CVE-2020-10969 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind