Логотип exploitDog
bind:CVE-2024-34345
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-34345

Количество 2

Количество 2

nvd логотип

CVE-2024-34345

больше 1 года назад

The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-38gf-rh2w-gmj7

почти 2 года назад

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-34345

The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-38gf-rh2w-gmj7

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

CVSS3: 8.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу