@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability
- Severity:
- High
Description
XML External entity injections could be possible, when running the provided XML Validator on arbitrary input.
Recommendation
Update the @cyclonedx/cyclonedx-library package to the latest compatible version. Followings are version details:
- Affected version(s): = 6.7.0
- Patched version(s): 6.7.1
References
Related Issues
- Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability - CVE-2024-35255
- Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability (GHSA-m5vv-6r4h-3vj9) - CVE-2024-35255
- Svelte has a potential mXSS vulnerability due to improper HTML escaping - CVE-2024-45047
- Strapi Improper Rate Limiting vulnerability - CVE-2023-38507
- Tags:
- npm
- @cyclonedx/cyclonedx-library
Anything's wrong? Let us know Last updated on May 14, 2024