apache / cordova-windows

[DEPRECATED] Apache Cordova Windows
Apache License 2.0
203 stars 171 forks source link

shelljs 0.5.3 is vulnerable #404

Closed JokHuang closed 1 year ago

JokHuang commented 2 years ago

Bug Report

Problem

cordova-windows 7.0.1 has shelljs 0.5.3, which is vulnerable to Improper Privilege Management

What is expected to happen?

upgrade the shelljs version to 0.8.5 or other which is not vulnerable

What does actually happen?

shelljs 0.5.3 is vulnerable to Improper Privilege Management

Information

https://nvd.nist.gov/vuln/detail/CVE-2022-0144

timbru31 commented 1 year ago

We are archiving this repository following Apache Cordova's Deprecation Policy. We will not continue to work on this repository. Therefore all issues and pull requests are being closed. Thanks for your contribution.