CVE-2022-31180
Summary
| CVE | CVE-2022-31180 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-01 20:15:00 UTC |
| Updated | 2023-07-24 13:07:00 UTC |
| Description | Shescape is a simple shell escape package for JavaScript. Affected versions were found to have insufficient escaping of white space when interpolating output. This issue only impacts users that use the `escape` or `escapeAll` functions with the `interpolation` option set to `true`. The result is that if an attacker is able to include whitespace in their input they can: 1. Invoke shell-specific behaviour through shell-specific special characters inserted directly after whitespace. 2. Invoke shell-specific behaviour through shell-specific special characters inserted or appearing after line terminating characters. 3. Invoke arbitrary commands by inserting a line feed character. 4. Invoke arbitrary commands by inserting a carriage return character. Behaviour number 1 has been patched in [v1.5.7] which you can upgrade to now. No further changes are required. Behaviour number 2, 3, and 4 have been patched in [v1.5.8] which you can upgrade to now. No further changes are required. The best workaround is to avoid having to use the `interpolation: true` option - in most cases using an alternative is possible, see [the recipes](https://github.com/ericcornelissen/shescape#recipes) for recommendations. Alternatively, users may strip all whitespace from user input. Note that this is error prone, for example: for PowerShell this requires stripping `'\u0085'` which is not included in JavaScript's definition of `\s` for Regular Expressions. |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Shescape Project | Shescape | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Release v1.5.7 · ericcornelissen/shescape · GitHub | MISC | github.com | |
| Release Release v1.5.8 · ericcornelissen/shescape · GitHub | MISC | github.com | |
| Escaping for Unix shells after whitespace with `{interpolation:true}` by ericcornelissen · Pull Request #324 · ericcornelissen/shescape · GitHub | MISC | github.com | |
| Insufficient escaping of whitespace · Advisory · ericcornelissen/shescape · GitHub | CONFIRM | github.com | |
| Escaping for PowerShell after whitespace with `{interpolation:true}` by ericcornelissen · Pull Request #322 · ericcornelissen/shescape · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.