PT-2024-34357 · Unknown+3 · Owasp Dep-Scan+3
Eran-Medan
·
Published
2024-10-27
·
Updated
2025-02-02
·
CVE-2024-50611
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
CycloneDX cdxgen versions prior to 11.1.7
Description:
The issue allows execution of code contained within build-related files, such as
build.gradle.kts, when run against an untrusted codebase. This is similar to a previously identified issue. The cdxgen tool is used by various applications, including OWASP dep-scan. It has been noted that this is a design limitation rather than an implementation mistake.Recommendations:
For versions prior to 11.1.7, update to version 11.1.7 or later, which introduces a "secure mode" that uses Node.js permissions to control resource access, limiting file access and process execution.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cyclonedx
Node.Js
Owasp Dep-Scan
Cdxgen