Shescape potential environment variable exposure on Windows with CMD
CVE-2023-35931

3.1LOW

Key Information:

Status
Vendor
CVE Published:
23 June 2023

What is CVE-2023-35931?

Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.

Affected Version(s)

shescape < 1.7.1

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.