diff --git a/lib/check_reqs.js b/lib/check_reqs.js index 903f3e4c..2422296b 100644 --- a/lib/check_reqs.js +++ b/lib/check_reqs.js @@ -110,7 +110,9 @@ module.exports.get_gradle_wrapper = function () { let program_dir; // OK, This hack only works on Windows, not on Mac OS or Linux. We will be deleting this eventually! if (module.exports.isWindows()) { - const result = execa.sync(path.join(__dirname, 'getASPath.bat')); + // "shell" option enabled for CVE-2024-27980 (Windows) Mitigation + // See https://nodejs.org/en/blog/vulnerability/april-2024-security-releases-2 for more details + const result = execa.sync(path.join(__dirname, 'getASPath.bat'), { shell: true }); // console.log('result.stdout =' + result.stdout.toString()); // console.log('result.stderr =' + result.stderr.toString());