Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2016-6793 Vulnerability in maven package org.apache.wicket:wicket-util
CVE-2021-35515 Vulnerability in maven package org.apache.commons:commons-compress
CVE-2023-47320 Vulnerability in maven package org.silverpeas.core:silverpeas-core-web
CVE-2017-5635 Vulnerability in maven package org.apache.nifi:nifi-framework-authorization
CVE-2022-43426 Vulnerability in maven package io.jenkins.plugins:s3explorer