Description
Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.
Remediation
References
https://github.com/ericcornelissen/shescape/pull/982
https://github.com/ericcornelissen/shescape/commit/d0fce70f987ac0d8331f93cb45d47e79436173ac
https://github.com/ericcornelissen/shescape/security/advisories/GHSA-3g7p-8qhx-mc8r
https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1
Related Vulnerabilities
CVE-2012-6662 Vulnerability in maven package org.fujion.webjars:jquery-ui
CVE-2023-30843 Vulnerability in npm package payload
CVE-2019-18213 Vulnerability in maven package org.lsp4xml:lsp4xml-extensions
CVE-2023-46604 Vulnerability in maven package org.apache.activemq:activemq-client
CVE-2021-43783 Vulnerability in npm package @backstage/plugin-scaffolder-backend