Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2018-14042 Vulnerability in npm package bootstrap-sass
CVE-2019-10434 Vulnerability in maven package com.mtvi.plateng.hudson:ldapemail
CVE-2018-25031 Vulnerability in npm package swagger-ui
CVE-2018-1322 Vulnerability in maven package org.apache.syncope:syncope-core
CVE-2020-6506 Vulnerability in maven package org.webjars.npm:react-native-webview