{"id":"GHSA-64g7-mvw6-v9qj","summary":"Improper Privilege Management in shelljs","details":"### Impact\nOutput from the synchronous version of `shell.exec()` may be visible to other users on the same system. You may be affected if you execute `shell.exec()` in multi-user Mac, Linux, or WSL environments, or if you execute `shell.exec()` as the root user.\n\nOther shelljs functions (including the asynchronous version of `shell.exec()`) are not impacted.\n\n### Patches\nPatched in shelljs 0.8.5\n\n### Workarounds\nRecommended action is to upgrade to 0.8.5.\n\n### References\nhttps://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c/\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Ask at https://github.com/shelljs/shelljs/issues/1058\n* Open an issue at https://github.com/shelljs/shelljs/issues/new\n","modified":"2022-01-14T20:50:57Z","published":"2022-01-14T21:09:50Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-269"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-01-14T20:50:57Z"},"references":[{"type":"WEB","url":"https://github.com/shelljs/shelljs/security/advisories/GHSA-64g7-mvw6-v9qj"},{"type":"PACKAGE","url":"https://github.com/shelljs/shelljs"},{"type":"WEB","url":"https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c"}],"affected":[{"package":{"name":"shelljs","ecosystem":"npm","purl":"pkg:npm/shelljs"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.8.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-64g7-mvw6-v9qj/GHSA-64g7-mvw6-v9qj.json"}}],"schema_version":"1.9.0"}