Description
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/703415
Related Vulnerabilities
CVE-2020-2288 Vulnerability in maven package org.jenkins-ci.plugins:audit-trail
CVE-2020-2285 Vulnerability in maven package org.jenkins-ci.plugins:liquibase-runner
CVE-2019-1003053 Vulnerability in maven package org.jenkins-ci.plugins:hockeyapp
CVE-2019-10241 Vulnerability in maven package org.eclipse.jetty.aggregate:jetty-all