{"id":"GHSA-64g7-mvw6-v9qj","aliases":[],"url":"https://o3.security/vulnerability/GHSA-64g7-mvw6-v9qj","summary":"Improper Privilege Management in shelljs","details":"### Impact\nOutput from the synchronous version of `shell.exec()` may be visible to other users on the same system. You may be affected if you execute `shell.exec()` in multi-user Mac, Linux, or WSL environments, or if you execute `shell.exec()` as the root user.\n\nOther shelljs functions (including the asynchronous version of `shell.exec()`) are not impacted.\n\n### Patches\nPatched in shelljs 0.8.5\n\n### Workarounds\nRecommended action is to upgrade to 0.8.5.\n\n### References\nhttps://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Ask at https://github.com/shelljs/shelljs/issues/1058\n* Open an issue at https://github.com/shelljs/shelljs/issues/new\n","published":"2022-01-14T21:09:50Z","modified":"2022-01-14T20:50:57Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"shelljs","fixedVersion":"0.8.5"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/shelljs/shelljs/security/advisories/GHSA-64g7-mvw6-v9qj"},{"type":"PACKAGE","url":"https://github.com/shelljs/shelljs"},{"type":"WEB","url":"https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-01-14T20:50:57Z"}}