Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2022-36899 Vulnerability in maven package com.compuware.jenkins:compuware-ispw-operations
CVE-2021-29469 Vulnerability in npm package redis
CVE-2017-15712 Vulnerability in maven package org.apache.oozie:oozie-core
CVE-2020-17527 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core