Description
npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user
Remediation
References
https://nodesecurity.io/advisories/336
Related Vulnerabilities
CVE-2020-28462 Vulnerability in npm package ion-parser
CVE-2021-22096 Vulnerability in maven package org.springframework:spring-core
CVE-2021-23358 Vulnerability in npm package underscore
CVE-2018-3749 Vulnerability in maven package org.webjars.npm:deap
CVE-2018-1335 Vulnerability in maven package org.apache.tika:tika-server