漏洞信息详情
CycloneDX BOM Repository Server 安全漏洞
漏洞简介
CycloneDX BOM Repository Server是一个 BOM 存储库服务器。用于分发 CycloneDX BOM。
CycloneDX BOM Repository Server 2.0.1之前版本存在安全漏洞,该漏洞源于不正确的输入验证导致路径遍历问题。攻击者利用该漏洞可以创建任意目录或删除任意目录导致拒绝服务。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/CycloneDX/cyclonedx-bom-repo-server/security/advisories/GHSA-6c74-9588-wq9j
参考网址
来源:CONFIRM
链接:https://github.com/CycloneDX/cyclonedx-bom-repo-server/security/advisories/GHSA-6c74-9588-wq9j
来源:MISC
链接:https://github.com/CycloneDX/cyclonedx-bom-repo-server/releases/tag/v2.0.1
来源:MISC
链接:https://github.com/CycloneDX/cyclonedx-bom-repo-server/commit/001a3278b5572e52c0ecac0bd1157bf2599502b7
来源:cxsecurity.com
链接:https://cxsecurity.com/cveshow/CVE-2022-24774/
受影响实体
暂无
补丁
- CycloneDX BOM Repository Server 安全漏洞的修复措施<!--2022-3-22-->
还没有评论,来说两句吧...