CVE-2024-50611 Information

Description

CycloneDX cdxgen through 10.10.7 when run against an untrusted codebase may execute code contained within build-related files such as build.gradle.kts a similar issue to CVE-2022-24441. cdxgen is used by for example OWASP dep-scan. NOTE: this has been characterized as a design limitation rather than an implementation mistake.

Reference

https://github.com/CycloneDX/cdxgen/releases https://github.com/CycloneDX/cdxgen/issues/1328 https://owasp.org/www-project-dep-scan/

Share on: