Executive brief
CycloneDX cdxgen is a tool that generates software component documentation for supply chain security analysis, commonly used in OWASP dependency scanning. When analyzing untrusted codebases, the tool executes code from build configuration files (such as build.gradle.kts), allowing an attacker to run arbitrary code with the privileges of the user running cdxgen.
Technical details
CycloneDX cdxgen versions prior to 11.1.7 are vulnerable to arbitrary code execution via Improper Control of Dynamically-Managed Code Resources (CWE-94). The root cause is that the tool executes code from build-related files (e.g., build.gradle.kts) when analyzing a codebase, a design limitation rather than an implementation error. The attack vector is local and requires a high-privilege user or high user interaction level. An attacker can craft a malicious build file in an untrusted repository that, when processed by cdxgen, executes arbitrary code with the privileges of the scanning process. The fix is available in version 11.1.7 and later.
Affected products
- CycloneDX cdxgen < 11.1.7
Timeline
- 2024-10-28: disclosed
- 2024-10-28: patched: Version 11.1.7 released