Description
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/703415
Related Vulnerabilities
CVE-2021-27516 Vulnerability in maven package org.webjars.bower:urijs
CVE-2021-23900 Vulnerability in maven package com.mikesamuel:json-sanitizer
CVE-2021-3632 Vulnerability in maven package org.keycloak:keycloak-core
CVE-2018-5653 Vulnerability in maven package org.apache.cayenne.modeler:cayenne-modeler
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-worker