VDB
Sign up
HIGH7.5

GHSA-6fhj-vr9j-g45r

CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection

Quick fix

GHSA-6fhj-vr9j-g45r — org.cyclonedx:cyclonedx-core-java: upgrade to the fixed version with the command below.

# pom.xml: bump <version>11.0.1</version> for org.cyclonedx:cyclonedx-core-java

Details

### Impact

The XML [`Validator`](https://docs.oracle.com/javase/8/docs/api/javax/xml/validation/Validator.html) used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML External Entity (XXE) injection.

The fix for GHSA-683x-4444-jxh8 / CVE-2024-38374 has been incomplete in that it only fixed *parsing* of XML BOMs, but not *validation*.

### Patches

The vulnerability has been fixed in cyclonedx-core-java version 11.0.1.

### Workarounds

If feasible, applications can reject XML documents before handing them to cyclonedx-core-java for validation. This may be an option if incoming CycloneDX BOMs are known to be in JSON format.

### References

* The issue was introduced via https://github.com/CycloneDX/cyclonedx-core-java/commit/162aa594f347b3f612fe0a45071693c3cd398ce9 * The issue was fixed via https://github.com/CycloneDX/cyclonedx-core-java/pull/737 * https://cheatsheetseries.owasp.org/cheatsheets/XML_External_Entity_Prevention_Cheat_Sheet.html#schemafactory

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.cyclonedx:cyclonedx-core-java
Introduced in: 2.1.0Fixed in: 11.0.1
Fix# pom.xml: bump <version>11.0.1</version> for org.cyclonedx:cyclonedx-core-java

References