Description
In Limdu before 0.95, the trainBatch function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. This has been patched in 0.95.
Remediation
References
https://github.com/erelsgl/limdu/security/advisories/GHSA-77qv-gh6f-pgh4
Related Vulnerabilities
CVE-2013-5855 Vulnerability in maven package javax.faces:jsf-impl
CVE-2021-21366 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2011-1184 Vulnerability in maven package tomcat:catalina
CVE-2017-5929 Vulnerability in maven package ch.qos.logback:logback-core
CVE-2020-9488 Vulnerability in maven package org.apache.logging.log4j:log4j