PT-2024-26308 · Bombastic · Bombastic

Rohit Keshri

·

Published

2024-04-25

·

Updated

2025-06-18

·

CVE-2024-3508

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Bombastic (affected versions not specified)
Description A flaw was found in Bombastic, allowing authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-3508

Affected Products

Bombastic