Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc7w-4cjf-c973

Опубликовано: 12 окт. 2021
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

OS Command Injection in node-opencv

utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.

Пакеты

Наименование

opencv

npm
Затронутые версииВерсия исправления

< 6.1.0

6.1.0

EPSS

Процентиль: 93%
0.10469
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 7 лет назад

utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.

CVSS3: 9.8
nvd
почти 7 лет назад

utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.

CVSS3: 9.8
debian
почти 7 лет назад

utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) ...

EPSS

Процентиль: 93%
0.10469
Средний

9.8 Critical

CVSS3

Дефекты

CWE-78