Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2022-23059 Vulnerability in maven package com.shopizer:shopizer
CVE-2021-44906 Vulnerability in maven package org.webjars.npm:minimist
CVE-2023-34615 Vulnerability in maven package net.pwall.json:jsonutil
CVE-2017-16036 Vulnerability in npm package badjs-sourcemap-server
CVE-2022-31070 Vulnerability in npm package @finastra/nestjs-proxy