From ca8ce9280f809747e1e82eaa907510daf5068cb8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Wed, 26 Mar 2025 14:55:09 +0000 Subject: [PATCH] Publish Advisories GHSA-66pp-5p9w-q87j GHSA-7287-grhx-542x --- .../GHSA-66pp-5p9w-q87j.json | 73 +++++++++++++++++++ .../GHSA-7287-grhx-542x.json | 33 ++++++++- 2 files changed, 102 insertions(+), 4 deletions(-) create mode 100644 advisories/github-reviewed/2025/03/GHSA-66pp-5p9w-q87j/GHSA-66pp-5p9w-q87j.json rename advisories/{unreviewed => github-reviewed}/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json (64%) diff --git a/advisories/github-reviewed/2025/03/GHSA-66pp-5p9w-q87j/GHSA-66pp-5p9w-q87j.json b/advisories/github-reviewed/2025/03/GHSA-66pp-5p9w-q87j/GHSA-66pp-5p9w-q87j.json new file mode 100644 index 00000000000..7be280eb3dd --- /dev/null +++ b/advisories/github-reviewed/2025/03/GHSA-66pp-5p9w-q87j/GHSA-66pp-5p9w-q87j.json @@ -0,0 +1,73 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-66pp-5p9w-q87j", + "modified": "2025-03-26T14:54:22Z", + "published": "2025-03-26T14:54:22Z", + "aliases": [ + "CVE-2025-30222" + ], + "summary": "Shescape has potential environment variable exposure on Windows with CMD", + "details": "### Impact\n\nThis impact users of Shescape on Windows that explicitly configure `shell: 'cmd.exe'` or `shell: true` using any of `quote`/`quoteAll`/`escape`/`escapeAll`.\n\nAn attacker may be able to get read-only access to environment variables. Example:\n\n```javascript\nimport * as cp from \"node:child_process\";\nimport { Shescape } from \"shescape\";\n\n// 1. Prerequisites\nconst shescape = new Shescape({\n shell: \"cmd.exe\",\n // Or\n shell: true, // Only if the default shell is CMD\n});\n\n// 2. Payload\nconst payload = '\"%PATH%';\n\n// 3. Usage\nlet escapedPayload;\n\nescapedPayload = shescape.quote(payload);\n// Or\nescapedPayload = shescape.quoteAll([payload]);\n// Or\nescapedPayload = shescape.escape(payload);\n// Or\nescapedPayload = shescape.escapeAll([payload]);\n\n// And (example)\nconst result = cp.execSync(`echo Hello ${escapedPayload}`, options);\n\n// 4. Impact\nconsole.log(result.toString());\n// Outputs \"Hello\" followed by the contents of the PATH environment variable\n```\n\nFor Shescape prior to v2.0.0, the `options` object must have `shell: 'cmd.exe'` or `shell: undefined` and `interpolation: true`.\n\n\n### Patches\n\nThis bug has been patched in [v2.1.2](https://github.com/ericcornelissen/shescape/releases/tag/v2.1.2) which you can upgrade to now.\n\nIf you are already using v2 of Shescape, no further changes are required. If you are using v1 of Shescape, follow the [migration guide](https://github.com/ericcornelissen/shescape/blob/155b13b4141750203ce71249f1b0fdc638c7a0d0/docs/migration.md) to upgrade to v2. There is no plan to release a patch compatible with v1 of Shescape.\n\n\n### Workarounds\n\nAlternatively, users can remove all instances of % from user input before using Shescape.\n\n\n### References\n\n- Shescape Pull Request [#1916](https://github.com/ericcornelissen/shescape/pull/1916)\n- Shescape commit [0a81f1e](https://github.com/ericcornelissen/shescape/commit/0a81f1eb077bab8caae283a2490cd7be9af179c6)\n- Shescape release [v2.1.2](https://github.com/ericcornelissen/shescape/releases/tag/v2.1.2)\n\n\n### For more information\n\n- Comment on Pull Request [#1916](https://github.com/ericcornelissen/shescape/pull/1916)\n- Comment on commit [0a81f1e](https://github.com/ericcornelissen/shescape/commit/0a81f1eb077bab8caae283a2490cd7be9af179c6)\n- Open an issue at [https://github.com/ericcornelissen/shescape/issues](https://github.com/ericcornelissen/shescape/issues) (New issue > Question)", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U" + } + ], + "affected": [ + { + "package": { + "ecosystem": "npm", + "name": "shescape" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "1.7.2" + }, + { + "fixed": "2.1.2" + } + ] + } + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/security/advisories/GHSA-66pp-5p9w-q87j" + }, + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30222" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/pull/1916" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/commit/0a81f1eb077bab8caae283a2490cd7be9af179c6" + }, + { + "type": "PACKAGE", + "url": "https://github.com/ericcornelissen/shescape" + }, + { + "type": "WEB", + "url": "https://github.com/ericcornelissen/shescape/releases/tag/v2.1.2" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-03-26T14:54:22Z", + "nvd_published_at": "2025-03-25T23:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json b/advisories/github-reviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json similarity index 64% rename from advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json rename to advisories/github-reviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json index 4fc1f4b120f..67d2576f346 100644 --- a/advisories/unreviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json +++ b/advisories/github-reviewed/2025/03/GHSA-7287-grhx-542x/GHSA-7287-grhx-542x.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-7287-grhx-542x", - "modified": "2025-03-25T21:31:34Z", + "modified": "2025-03-26T14:53:15Z", "published": "2025-03-25T21:31:34Z", "aliases": [ "CVE-2025-30741" ], + "summary": "Pixelfed may allow unauthorized actor to view private posts and private users", "details": "Pixelfed before 0.12.5 allows anyone to follow private accounts and see private posts on other Fediverse servers. This affects users elsewhere in the Fediverse, if they otherwise have any followers from a Pixelfed instance.", "severity": [ { @@ -13,7 +14,27 @@ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N" } ], - "affected": [], + "affected": [ + { + "package": { + "ecosystem": "Packagist", + "name": "pixelfed/pixelfed" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "0.12.5" + } + ] + } + ] + } + ], "references": [ { "type": "ADVISORY", @@ -23,6 +44,10 @@ "type": "WEB", "url": "https://fokus.cool/2025/03/25/pixelfed-vulnerability.html" }, + { + "type": "PACKAGE", + "url": "https://github.com/pixelfed/pixelfed" + }, { "type": "WEB", "url": "https://github.com/pixelfed/pixelfed/releases/tag/v0.12.5" @@ -41,8 +66,8 @@ "CWE-863" ], "severity": "MODERATE", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2025-03-26T14:53:15Z", "nvd_published_at": "2025-03-25T21:15:43Z" } } \ No newline at end of file