Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @cyclonedx/cdxgen to version 12.3.3 or higher.
@cyclonedx/cdxgen is a Creates CycloneDX Software Bill of Materials (SBOM) from source or container image
Affected versions of this package are vulnerable to Use of Incorrectly-Resolved Name or Reference in path resolution performed in docker.js, before credential selection. An attacker who controls a malicious public registry whose hostname is a suffix (right side substring) match for a private registry for which a user has credentials in the X-Registry-Auth header, can expose those private registry credentials by convincing the user to scan or pull an image from the malicious registry.