Description
If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.
Remediation
References
https://hackerone.com/reports/389561
Related Vulnerabilities
CVE-2022-23539 Vulnerability in maven package org.webjars.npm:jsonwebtoken
CVE-2022-23496 Vulnerability in maven package nl.basjes.parse.useragent:yauaa-beam
CVE-2023-2251 Vulnerability in npm package yaml
CVE-2020-26301 Vulnerability in npm package ssh2
CVE-2021-38294 Vulnerability in maven package org.apache.storm:storm-server