cve/2022/CVE-2022-0144.md
2024-06-18 02:51:15 +02:00

21 lines
742 B
Markdown

### [CVE-2022-0144](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0144)
![](https://img.shields.io/static/v1?label=Product&message=shelljs%2Fshelljs&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%200.8.5%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-269%20Improper%20Privilege%20Management&color=brighgreen)
### Description
shelljs is vulnerable to Improper Privilege Management
### POC
#### Reference
- https://huntr.dev/bounties/50996581-c08e-4eed-a90e-c0bac082679c
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/Haxatron/Haxatron
- https://github.com/tomjfrog-org/frogbot-npm-demo
- https://github.com/tomjfrog/frogbot-demo