Описание
Command Injection in opencv
Versions of opencvprior to 6.1.0 are vulnerable to Command Injection. The utils/ script find-opencv.js does not validate user input allowing attackers to execute arbitrary commands.
Recommendation
Upgrade to version 6.1.0.
Пакеты
Наименование
opencv
npm
Затронутые версииВерсия исправления
< 6.1.0
6.1.0
Дефекты
CWE-77
Дефекты
CWE-77