CVE-2022-0144

NameCVE-2022-0144
Descriptionshelljs is vulnerable to Improper Privilege Management
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-shelljs (PTS)buster, bullseye0.8.3-1vulnerable
bookworm, sid, trixie0.8.5+~cs0.8.10-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-shelljssourcestretch(unfixed)end-of-life
node-shelljssource(unstable)0.8.5+~cs0.8.10-1

Notes

[bullseye] - node-shelljs <no-dsa> (Minor issue)
[buster] - node-shelljs <no-dsa> (Minor issue)
[stretch] - node-shelljs <end-of-life> (Nodejs in stretch not covered by security support)
https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c/
https://github.com/shelljs/shelljs/issues/1058
https://github.com/shelljs/shelljs/commit/d919d22dd6de385edaa9d90313075a77f74b338c (v0.8.5)

Search for package or bug name: Reporting problems