Description
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.
Remediation
References
https://github.com/lessthanoptimal/BoofCV/issues/406
Related Vulnerabilities
CVE-2022-24897 Vulnerability in maven package org.xwiki.commons:xwiki-commons-velocity
CVE-2022-25912 Vulnerability in maven package org.webjars.npm:simple-git
CVE-2020-28477 Vulnerability in npm package immer
CVE-2021-40660 Vulnerability in maven package org.javadelight:delight-nashorn-sandbox
CVE-2018-19048 Vulnerability in maven package org.webjars:simditor