@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability
- Severity:
- High
Description
XML External entity injections could be possible, when running the provided XML Validator on arbitrary input.
Recommendation
Update the @cyclonedx/cyclonedx-library package to the latest compatible version. Followings are version details:
- Affected version(s): = 6.7.0
- Patched version(s): 6.7.1
References
Related Issues
- Svelte has a potential mXSS vulnerability due to improper HTML escaping - CVE-2024-45047
- Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability - CVE-2024-35255
- TinyMCE Cross-Site Scripting (XSS) vulnerability in handling external SVG files through Object or Embed elements - CVE-2024-29881
- Cross-site scripting vulnerability in TinyMCE plugins - CVE-2024-21910
You might also like:
- Tags:
- npm
- @cyclonedx/cyclonedx-library
Anything's wrong? Let us know Last updated on May 14, 2024


