A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.
History

Wed, 16 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-04-25T17:46:21.762Z

Updated: 2024-10-16T15:01:49.913Z

Reserved: 2024-04-09T08:03:26.957Z

Link: CVE-2024-3508

cve-icon Vulnrichment

Updated: 2024-08-01T20:12:07.548Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-25T18:15:09.567

Modified: 2024-11-21T09:29:45.263

Link: CVE-2024-3508

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-04-09T00:00:00Z

Links: CVE-2024-3508 - Bugzilla