Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1oeGYzLXZncG0tZnY5cM4ABAsl
CycloneDX cdxgen may execute code contained within build-related files
CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a design limitation, rather than an implementation mistake.
Permalink: https://github.com/advisories/GHSA-hxf3-vgpm-fv9pJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1oeGYzLXZncG0tZnY5cM4ABAsl
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: 10 days ago
Updated: 7 days ago
CVSS Score: 7.4
CVSS vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Identifiers: GHSA-hxf3-vgpm-fv9p, CVE-2024-50611
References:
- https://nvd.nist.gov/vuln/detail/CVE-2024-50611
- https://github.com/CycloneDX/cdxgen/issues/1328
- https://github.com/CycloneDX/cdxgen/releases
- https://owasp.org/www-project-dep-scan
- https://github.com/advisories/GHSA-hxf3-vgpm-fv9p
Blast Radius: 0.0
Affected Packages
npm:@cyclonedx/cdxgen
Dependent packages: 0Dependent repositories: 1
Downloads: 177,439 last month
Affected Version Ranges: <= 10.10.7
No known fixed version
All affected versions: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.4, 8.0.5, 8.0.6, 8.1.0, 8.1.1, 8.1.2, 8.1.3, 8.1.4, 8.1.5, 8.1.6, 8.1.7, 8.1.8, 8.1.9, 8.2.0, 8.2.1, 8.2.2, 8.2.3, 8.2.4, 8.3.0, 8.3.1, 8.3.2, 8.3.3, 8.4.0, 8.4.1, 8.4.2, 8.4.3, 8.4.6, 8.4.7, 8.4.8, 8.4.9, 8.4.10, 8.4.11, 8.4.12, 8.4.13, 8.5.0, 8.5.1, 8.5.2, 8.5.3, 8.6.0, 8.6.1, 8.6.2, 8.6.3, 9.0.0, 9.0.1, 9.1.0, 9.1.1, 9.2.0, 9.2.1, 9.2.2, 9.3.0, 9.3.1, 9.3.2, 9.4.0, 9.5.0, 9.6.0, 9.6.1, 9.7.0, 9.7.1, 9.7.3, 9.7.5, 9.8.0, 9.8.1, 9.8.2, 9.8.3, 9.8.4, 9.8.5, 9.8.6, 9.8.7, 9.8.8, 9.8.9, 9.8.10, 9.9.0, 9.9.1, 9.9.2, 9.9.3, 9.9.4, 9.9.5, 9.9.6, 9.9.7, 9.9.8, 9.9.9, 9.10.0, 9.10.1, 9.10.2, 9.11.0, 9.11.1, 9.11.2, 9.11.3, 9.11.4, 9.11.5, 9.11.6, 10.0.0, 10.0.1, 10.0.2, 10.0.3, 10.0.4, 10.0.5, 10.0.6, 10.1.0, 10.1.1, 10.1.2, 10.1.3, 10.2.1, 10.2.2, 10.2.3, 10.2.4, 10.2.5, 10.2.6, 10.3.0, 10.3.1, 10.3.2, 10.3.3, 10.3.4, 10.3.5, 10.4.0, 10.4.1, 10.4.2, 10.4.3, 10.5.0, 10.5.1, 10.5.2, 10.6.1, 10.6.2, 10.7.0, 10.7.1, 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.8.7, 10.8.8, 10.8.9, 10.9.0, 10.9.1, 10.9.2, 10.9.3, 10.9.4, 10.9.5, 10.9.6, 10.9.7, 10.9.8, 10.9.9, 10.9.10, 10.9.11, 10.10.0, 10.10.1, 10.10.2, 10.10.3, 10.10.4, 10.10.5, 10.10.6, 10.10.7