Executive brief
The CycloneDX JavaScript library, which is used to handle Software Bill of Materials (SBOM) data, contains a vulnerability in its XML validation component. If an application uses this library to validate a maliciously crafted XML file, an attacker could potentially read sensitive files from the server or cause other unintended behaviors. This could lead to the exposure of internal system data or configuration files.
Technical details
An Improper Restriction of XML External Entity Reference (XXE) vulnerability (CWE-611) exists in the @cyclonedx/cyclonedx-library within the XmlValidator component. The vulnerability was introduced in version 6.7.0 when the library failed to disable external entity resolution during XML validation. A remote, unauthenticated attacker can exploit this by providing a forged CycloneDX BOM file containing a DOCTYPE declaration with a SYSTEM entity pointing to local files (e.g., /etc/passwd). When the validator processes this input, it may resolve the entity and include the file contents in its output or behavior. The issue is resolved in version 6.7.1 by preventing the parser from resolving external entities.
Affected products
- CycloneDX @cyclonedx/cyclonedx-library 6.7.0
Timeline
- 2024-05-07: patched: Fix merged into main branch via PR 1063
- 2024-05-08: disclosed: GitHub Security Advisory published
- 2024-05-14: advisory: NVD published CVE-2024-34345
References
- https://github.com/CycloneDX/cyclonedx-javascript-library/security/advisories/GHSA-38gf-rh2w-gmj7
- https://github.com/CycloneDX/cyclonedx-javascript-library/pull/1063
- https://github.com/CycloneDX/cyclonedx-javascript-library/commit/5e5e1e0b9422f47d2de81c7c4064b803a01e7203
- https://github.com/CycloneDX/cyclonedx-javascript-library