CVE-2022-014411.01.2022, 07:15shelljs is vulnerable to Improper Privilege ManagementEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST7.1 HIGHLOCALLOWLOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H@huntrdevCNA7.1 HIGHLOCALLOWLOWCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HCVEADP------Base ScoreCVSS 3.xEPSS ScorePercentile: 34%VendorProductVersionshelljs_projectshelljs𝑥< 0.8.5𝑥= Vulnerable software versionsDebian ReleasesDebian ProductCodenamenode-shelljsbullseyeno-dsabusterno-dsasid0.8.5+~cs0.8.10-2fixedtrixie0.8.5+~cs0.8.10-2fixedbookworm0.8.5+~cs0.8.10-2fixedUbuntu ReleasesUbuntu ProductCodenamenode-shelljsnoblenot-affectedmanticnot-affectedlunarnot-affectedkineticnot-affectedjammynot-affectedimpishignoredhirsuteignoredfocalneeds-triagebionicneeds-triagexenialignoredtrustyignoredKnown Exploits!https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679chttps://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679cCommon Weakness EnumerationCWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.Referenceshttps://github.com/shelljs/shelljs/commit/d919d22dd6de385edaa9d90313075a77f74b338chttps://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679chttps://github.com/shelljs/shelljs/commit/d919d22dd6de385edaa9d90313075a77f74b338chttps://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c