QID 984089
QID 984089: Nodejs (npm) Security Update for limdu (GHSA-77qv-gh6f-pgh4)
Security update has been released for limdu to fix the vulnerability. Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
The `trainBatch` function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.
Solution
Patched in version 0.95.Workaround:
Do not use trainBatch with classifiers that rely on shell execution, such as SVM Perf, SVM Linear or Adaboost
Do not use trainBatch with classifiers that rely on shell execution, such as SVM Perf, SVM Linear or Adaboost
Vendor References
- GHSA-77qv-gh6f-pgh4 -
github.com/advisories/GHSA-77qv-gh6f-pgh4
CVEs related to QID 984089
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-77qv-gh6f-pgh4 | limdu |
|