PT-2024-34357 · Cdxgen+3 · Cdxgen+3

·

CVE-2024-50611

·

Published

2024-10-27

·

Updated

2025-02-02

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: CycloneDX cdxgen versions prior to 11.1.7
Description: The issue allows execution of code contained within build-related files, such as build.gradle.kts, when run against an untrusted codebase. This is similar to a previously identified issue. The cdxgen tool is used by various applications, including OWASP dep-scan. It has been noted that this is a design limitation rather than an implementation mistake.
Recommendations: For versions prior to 11.1.7, update to version 11.1.7 or later, which introduces a "secure mode" that uses Node.js permissions to control resource access, limiting file access and process execution.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-50611
GHSA-HXF3-VGPM-FV9P

Affected Products

Cyclonedx
Node.Js
Owasp Dep-Scan
Cdxgen