Description
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
Remediation
References
https://hackerone.com/reports/390848
Related Vulnerabilities
CVE-2022-31777 Vulnerability in maven package org.apache.spark:spark-core_2.13
CVE-2021-21160 Vulnerability in maven package org.webjars.npm:electron
CVE-2019-12041 Vulnerability in maven package org.webjars.bower:remarkable
CVE-2023-22894 Vulnerability in npm package @strapi/strapi
CVE-2019-19919 Vulnerability in maven package org.webjars.npm:handlebars