QID 980431
QID 980431: Nodejs (npm) Security Update for opencv (GHSA-mc7w-4cjf-c973)
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-mc7w-4cjf-c973 for updates pertaining to this vulnerability.
Vendor References
- GHSA-mc7w-4cjf-c973 -
github.com/advisories/GHSA-mc7w-4cjf-c973
CVEs related to QID 980431
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-mc7w-4cjf-c973 | opencv |
|