Arbitrary Command Injection Affecting opencv package, versions <6.1.0
Threat Intelligence
EPSS
0.56% (79th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-OPENCV-174005
- published 26 Mar 2019
- disclosed 20 Mar 2019
- credit Unknown
Introduced: 20 Mar 2019
CVE-2019-10061 Open this link in a new tabHow to fix?
Upgrade opencv
to version 6.1.0 or higher.
Overview
opencv is a defacto computer vision library - by interfacing with it natively in node, we get powerful real time vision in js.
Affected versions of this package are vulnerable to Arbitrary Command Injection. It did not properly validate user input which allowed attackers to execute arbitrary commands.
References
CVSS Scores
version 3.1