CVE-2019-10061
published 2019-03-26CVE-2019-10061: utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input…
PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.24%
90.0th percentile
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-opencv | < node-opencv 6.0.0+git20180416.cfc96ba0-3 (bookworm) | node-opencv 6.0.0+git20180416.cfc96ba0-3 (bookworm) |
| node-opencv_project | node-opencv | < 6.1.0 | 6.1.0 |
| node-opencv_project | node-opencv | >= 0 < 6.0.0+git20180416.cfc96ba0-3 | 6.0.0+git20180416.cfc96ba0-3 |
| node-opencv_project | node-opencv | >= 0 < 6.0.0+git20180416.cfc96ba0-3 | 6.0.0+git20180416.cfc96ba0-3 |
| node-opencv_project | node-opencv | >= 0 < 6.0.0+git20180416.cfc96ba0-3 | 6.0.0+git20180416.cfc96ba0-3 |
| node-opencv_project | node-opencv | >= 0 < 6.0.0+git20180416.cfc96ba0-3 | 6.0.0+git20180416.cfc96ba0-3 |
| opencv | opencv | >= 0 < 6.1.0 | 6.1.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable file is utils/find-opencv.js in node-opencv; monitor for unsanitized user input being passed through this script as it enables arbitrary command injection ↗
- →Flag execution of node-opencv versions prior to 6.1.0 (upstream) or prior to 6.0.0+git20180416.cfc96ba0-3 (Debian); presence of the unpatched utils/find-opencv.js is the attack surface ↗
- ·Scope of exploitation is local; the command injection requires local access or the ability to influence input passed to utils/find-opencv.js ↗
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian9.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-10061: node-opencv - utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6...
vendor_debian·2019·CVSS 9.8
CVE-2019-10061 [CRITICAL] CVE-2019-10061: node-opencv - utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6...
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
Scope: local
bookworm: resolved (fixed in 6.0.0+git20180416.cfc96ba0-3)
bullseye: resolved (fixed in 6.0.0+git20180416.cfc96ba0-3)
forky: resolved (fixed in 6.0.0+git20180416.cfc96ba0-3)
sid: resolved (fixed in 6.0.0+git20180416.cfc96ba0-3)
trixie: resolved (fixed in 6.0.0+git20180416.cfc96ba0-3)
GHSA
OS Command Injection in node-opencv
ghsa·2021-10-12
CVE-2019-10061 [CRITICAL] CWE-78 OS Command Injection in node-opencv
OS Command Injection in node-opencv
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
OSV
OS Command Injection in node-opencv
osv·2021-10-12
CVE-2019-10061 [CRITICAL] OS Command Injection in node-opencv
OS Command Injection in node-opencv
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
OSV
CVE-2019-10061: utils/find-opencv
osv·2019-03-26·CVSS 9.8
CVE-2019-10061 [CRITICAL] CVE-2019-10061: utils/find-opencv
utils/find-opencv.js in node-opencv (aka OpenCV bindings for Node.js) prior to 6.1.0 is vulnerable to Command Injection. It does not validate user input allowing attackers to execute arbitrary commands.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/peterbraden/node-opencv/commit/81a4b8620188e89f7e4fc985f3c89b58d4bcc86bhttps://github.com/peterbraden/node-opencv/commit/aaece6921d7368577511f06c94c99dd4e9653563https://www.npmjs.com/advisories/789https://github.com/peterbraden/node-opencv/commit/81a4b8620188e89f7e4fc985f3c89b58d4bcc86bhttps://github.com/peterbraden/node-opencv/commit/aaece6921d7368577511f06c94c99dd4e9653563https://www.npmjs.com/advisories/789
2019-03-26
Published