Description
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.
Remediation
References
https://github.com/lessthanoptimal/BoofCV/issues/406
Related Vulnerabilities
CVE-2021-23363 Vulnerability in npm package kill-by-port
CVE-2018-8009 Vulnerability in maven package org.apache.hadoop:hadoop-common
CVE-2018-19056 Vulnerability in maven package org.webjars.npm:editor.md
CVE-2017-11467 Vulnerability in maven package com.orientechnologies:orientdb-core
CVE-2016-10735 Vulnerability in maven package org.webjars:bootstrap-sass