CVE-2023-40185
Shescape on Windows escaping may be bypassed in threaded context
Severity Score
8.6
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
shescape is simple shell escape library for JavaScript. This may impact users that use Shescape on Windows in a threaded context. The vulnerability can result in Shescape escaping (or quoting) for the wrong shell, thus allowing attackers to bypass protections depending on the combination of expected and used shell. This bug has been patched in version 1.7.4.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-08-09 CVE Reserved
- 2023-08-23 CVE Published
- 2024-09-24 EPSS Updated
- 2024-09-30 CVE Updated
- 2024-09-30 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
https://github.com/ericcornelissen/shescape/releases/tag/v1.7.4 | Release Notes |
URL | Date | SRC |
---|---|---|
https://github.com/ericcornelissen/shescape/security/advisories/GHSA-j55r-787p-m549 | 2024-09-30 |
URL | Date | SRC |
---|---|---|
https://github.com/ericcornelissen/shescape/commit/0b976dab645abf45ffd85e74a8c6e51ee2f42d63 | 2023-09-01 | |
https://github.com/ericcornelissen/shescape/pull/1142 | 2023-09-01 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Shescape Project Search vendor "Shescape Project" | Shescape Search vendor "Shescape Project" for product "Shescape" | < 1.7.4 Search vendor "Shescape Project" for product "Shescape" and version " < 1.7.4" | node.js |
Affected
| in | Microsoft Search vendor "Microsoft" | Windows Search vendor "Microsoft" for product "Windows" | - | - |
Safe
|