Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2024-34345

больше 2 лет назад

The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-38gf-rh2w-gmj7

больше 2 лет назад

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-34345

The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-38gf-rh2w-gmj7

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу