Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2021-36372 Vulnerability in maven package org.apache.ozone:ozone-common
CVE-2016-5725 Vulnerability in maven package com.jcraft:jsch
CVE-2023-30527 Vulnerability in maven package org.jenkins-ci.plugins:wso2id-oauth
CVE-2017-16179 Vulnerability in npm package dasafio
CVE-2017-16026 Vulnerability in maven package org.webjars:request