Description
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.
Remediation
References
https://github.com/lessthanoptimal/BoofCV/issues/406
Related Vulnerabilities
CVE-2020-28423 Vulnerability in npm package monorepo-build
CVE-2016-5018 Vulnerability in maven package org.apache.tomcat:jasper
CVE-2018-20822 Vulnerability in npm package node-sass
CVE-2021-21353 Vulnerability in maven package org.webjars.npm:pug-code-gen
CVE-2023-37754 Vulnerability in maven package tech.powerjob:powerjob-common