CVE-2024-50611Code Injection in Cdxgen

CWE-94Code Injection3 documents3 sources
Severity
7.2HIGHNVD
GHSA8.8OSV8.8
EPSS
0.1%
top 67.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 27
Latest updateOct 28

Description

CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a design limitation, rather than an implementation mistake.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages1 packages

npmcyclonedx/cdxgen< 11.1.7

🔴Vulnerability Details

2
OSV
CycloneDX cdxgen may execute code contained within build-related files2024-10-28
GHSA
CycloneDX cdxgen may execute code contained within build-related files2024-10-28
CVE-2024-50611 — Code Injection in Cyclonedx Cdxgen | cvebase