CRITICAL
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command
Published Dec 18, 2019
9.8
CRITICALCVSS 3.1
EPSS 2.74%
Description
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Affected products
- Vendor n/a Product Treekill Defaultn/a
- Version Not fixedStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Treekill | n/a |
|
- 1.0.0
No data.
No Red Hat product state for this CVE.
tree-kill
npm
Introduced 0 Fixed 1.2.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | tree-kill | 0 | 1.2.2 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4302 Advisory
- https://github.com/advisories/GHSA-j7fq-p9q7-5wfv Advisory
- https://github.com/node-modules/treekill/blob/master/index.js#L32
- https://github.com/pkrumins/node-tree-kill/commit/ff73dbf144c4c2daa67799a50dfff59cd455c63c
- https://github.com/pkrumins/node-tree-kill/issues/30
- https://github.com/pkrumins/node-tree-kill/pull/31
- https://hackerone.com/reports/701183
- https://hackerone.com/reports/703415 x_refsource_MISCPermissions RequiredThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15598
- https://security.snyk.io/vuln/SNYK-JS-TREEKILL-536781
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner hackerone
Published Dec 18, 2019
Updated Aug 5, 2024
Reserved Aug 26, 2019
Link CVE-2019-15598
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-4302 GHSA-J7FQ-P9Q7-5WFV Assigner hackerone
Published Dec 18, 2019
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2022-4302