{"id":"GHSA-99p5-qpqx-mhwc","summary":"Code injection in BoofCV","details":"BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.","aliases":["CVE-2023-39010"],"modified":"2024-02-16T08:24:23.990583Z","published":"2023-07-28T15:30:23Z","database_specific":{"github_reviewed_at":"2023-07-28T20:56:56Z","nvd_published_at":"2023-07-28T15:15:12Z","cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39010"},{"type":"WEB","url":"https://github.com/lessthanoptimal/BoofCV/issues/406"},{"type":"WEB","url":"https://github.com/lessthanoptimal/BoofCV/commit/0da6139ff69fd5a49359854ab01935d06c7f5aac"},{"type":"PACKAGE","url":"https://github.com/lessthanoptimal/BoofCV"}],"affected":[{"package":{"name":"org.boofcv:boofcv-core","ecosystem":"Maven","purl":"pkg:maven/org.boofcv/boofcv-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.1"}]}],"versions":["0.27","0.28","0.29","0.30","0.31","0.32","0.33","0.33.1","0.34","0.35","0.36","0.36.1","0.37","0.38","0.39","0.39.1","0.40","0.40.1","0.41","0.42","0.43"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-99p5-qpqx-mhwc/GHSA-99p5-qpqx-mhwc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}