LOW 3.8 npm
Command Injection in Limdu
GHSA-77qv-gh6f-pgh4 · CVE-2020-4066
Published · Modified
Description
Impact
The trainBatch function has a command injection vulnerability. Clients of the Limdu library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.
Patches
Patched in version 0.9.5.
Workarounds
Do not use trainBatch with classifiers that rely on shell execution, such as SVM Perf, SVM Linear or Adaboost
References
No
Ready to move
Start Securing
Free, no credit card | First findings in minutes