Vulnerabilities

1 via 1 paths

Dependencies

36

Source

GitHub

Find, fix and prevent vulnerabilities in your code.

Issue type
  • 1
  • 1
Severity
  • 2
Status
  • 2
  • 0
  • 0

medium severity

Improper Encoding or Escaping of Output

  • Vulnerable module: shescape
  • Introduced through: shescape@2.1.14

Detailed paths

  • Introduced through: @snyk/snyk-cocoapods-plugin@snyk/snyk-cocoapods-plugin › shescape@2.1.14
    Remediation: Upgrade to shescape@2.1.15.

Overview

shescape is a simple shell escape library

Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output via the getEscapeFunction logic in src/internal/unix/busybox.js. An attacker can reveal the user's home directory and alter how a command interprets an assignment-prefixed value by supplying input such as :~ or a=~ to escape or escapeAll when Unix shell escaping targets BusyBox sh. On affected Unix systems where shell is set to "sh" or true and /bin/sh points to BusyBox, the escaped tilde is expanded in assignment contexts instead of being treated as data, causing commands like V=...; echo $V to print : followed by the home path.

Remediation

Upgrade shescape to version 2.1.15, 3.0.2 or higher.

References

medium severity

MPL-2.0 license

  • Module: shescape
  • Introduced through: shescape@2.1.14

Detailed paths

  • Introduced through: @snyk/snyk-cocoapods-plugin@snyk/snyk-cocoapods-plugin › shescape@2.1.14

MPL-2.0 license