org.boofcv:ip@0.20 vulnerabilities

  • latest version

    0.26

  • first published

    11 years ago

  • latest version published

    8 years ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.boofcv:ip package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Arbitrary Code Injection

    org.boofcv:ip is a Java library for real-time computer vision and robotics applications.

    Affected versions of this package are vulnerable to Arbitrary Code Injection via the boofcv.io.calibration.CalibrationIO.load() function. An attacker can load a malicious YAML file as a camera calibration config.

    How to fix Arbitrary Code Injection?

    Upgrade org.boofcv:ip to version 0.44 or higher.

    [,0.44)