Vulnerabilities/

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

Severity:
High

Description

XML External entity injections could be possible, when running the provided XML Validator on arbitrary input.

Recommendation

Update the @cyclonedx/cyclonedx-library package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@cyclonedx/cyclonedx-library
Anything's wrong? Let us know Last updated on May 14, 2024

This issue is available in SmartScanner Professional

See Pricing