12.8.2
3 years ago
16 days ago
Known vulnerabilities in the @cyclonedx/cdxgen package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
@cyclonedx/cdxgen is a Creates CycloneDX Software Bill of Materials (SBOM) from source or container image Affected versions of this package are vulnerable to Arbitrary Argument Injection via the Maven project scanning process. An attacker can execute arbitrary shell commands by submitting a repository with module paths containing shell metacharacters, which are interpreted by the shell during command construction. This can lead to execution of unintended commands in the process context when scanning attacker-controlled Maven projects in both CLI and server modes. How to fix Arbitrary Argument Injection? Upgrade | <12.4.3 |
@cyclonedx/cdxgen is a Creates CycloneDX Software Bill of Materials (SBOM) from source or container image Affected versions of this package are vulnerable to Use of Incorrectly-Resolved Name or Reference in path resolution performed in How to fix Use of Incorrectly-Resolved Name or Reference? Upgrade | >=9.9.5 <12.3.3 |