Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-drill
CVE-2023-34455 Vulnerability in maven package org.xerial.snappy:snappy-java
CVE-2020-5258 Vulnerability in maven package org.webjars.bowergithub.dojo:dojo
CVE-2021-43841 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2019-10311 Vulnerability in maven package org.jenkins-ci.plugins:ansible-tower