/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-rfq7-3777-23gj

Published

Last updated

https://images.chainguard.dev/security/CGA-rfq7-3777-23gj
Package

jitsucom-jitsu

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2021-42740
  • GHSA-g4rg-993r-mgx7

Severity

9.8

Critical

CVSS CVSS_V3

References

  • https://nvd.nist.gov/vuln/detail/CVE-2021-42740

Updates

Status

Not affected

Justification

Vulnerable code not present

Impact

The version of shell-quote included in this package, version 1.7.3, is the patched version that resolves the vulnerability described in CVE GHSA-g4rg-993r-mgx7. Additionally, the @types/shell-quote package (version 1.7.1) only contains TypeScript type definitions, which are not executable and are used solely during development. Type packages like @types/shell-quote do not affect the runtime behavior or security of the project and have no impact on its security integrity.


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing