Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2018-1336 Vulnerability in maven package org.apache.tomcat:tomcat-util
CVE-2021-3632 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2021-43812 Vulnerability in npm package @auth0/nextjs-auth0
CVE-2017-16137 Vulnerability in maven package org.webjars.npm:debug
CVE-2022-34662 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-api