CVE-2023-35931
Shescape potential environment variable exposure on Windows with CMD
Severity Score
4.3
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-06-20 CVE Reserved
- 2023-06-23 CVE Published
- 2024-12-05 CVE Updated
- 2024-12-05 First Exploit
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-526: Cleartext Storage of Sensitive Information in an Environment Variable
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/ericcornelissen/shescape/releases/tag/v1.7.1 | Release Notes |
URL | Date | SRC |
---|---|---|
https://github.com/ericcornelissen/shescape/security/advisories/GHSA-3g7p-8qhx-mc8r | 2024-12-05 |
URL | Date | SRC |
---|---|---|
https://github.com/ericcornelissen/shescape/commit/d0fce70f987ac0d8331f93cb45d47e79436173ac | 2023-07-04 | |
https://github.com/ericcornelissen/shescape/pull/982 | 2023-07-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Shescape Project Search vendor "Shescape Project" | Shescape Search vendor "Shescape Project" for product "Shescape" | < 1.7.1 Search vendor "Shescape Project" for product "Shescape" and version " < 1.7.1" | node.js |
Affected
|