Description
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
Remediation
References
https://hackerone.com/reports/390848
Related Vulnerabilities
CVE-2022-0086 Vulnerability in npm package uppy
CVE-2020-7788 Vulnerability in maven package org.webjars.npm:ini
CVE-2020-13128 Vulnerability in maven package com.googlecode.gwtupload:gwtupload-project
CVE-2021-23364 Vulnerability in npm package browserslist
CVE-2019-1003083 Vulnerability in maven package org.jenkins-ci.plugins:gearman-plugin