shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell. This bug has been patched in version 1.7.4.
CVSS
No CVSS.
References
Configurations
No configuration.
History
23 Aug 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-23 21:15
Updated : 2023-08-24 02:02
NVD link : CVE-2023-40185
Mitre link : CVE-2023-40185
JSON object : View
Products Affected
No product.
CWE
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences