CVE-2023-35931: Shescape potential environment variable exposure on Windows with CMD
Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Shescapeto a version that resolves this vulnerability.Fixed in 1.7.1
Event History
Frequently Asked Questions
What is CVE-2023-35931?
CVE-2023-35931 is a vulnerability in the Shescape library for JavaScript that allows an attacker to gain read-only access to environment variables.
What software is affected by CVE-2023-35931?
Shescape library versions up to and excluding 1.7.1 are affected by CVE-2023-35931.
How severe is CVE-2023-35931?
CVE-2023-35931 has a severity rating of 4.3, which is medium.
How can I fix CVE-2023-35931?
To fix CVE-2023-35931, update your Shescape library to version 1.7.1 or later.
Where can I find more information about CVE-2023-35931?
You can find more information about CVE-2023-35931 in the following references: [link1], [link2], [link3].