Vulnerabilities (CVE)

Filtered by vendor Cyclonedx
Filtered by product Bill Of Materials Repository Server
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-24774 1 Cyclonedx 1 Bill Of Materials Repository Server 2024-11-21 5.5 MEDIUM 7.1 HIGH
CycloneDX BOM Repository Server is a bill of materials (BOM) repository server for distributing CycloneDX BOMs. CycloneDX BOM Repository Server before version 2.0.1 has an improper input validation vulnerability leading to path traversal. A malicious user may potentially exploit this vulnerability to create arbitrary directories or a denial of service by deleting arbitrary directories. The vulnerability is resolved in version 2.0.1. The vulnerability is not exploitable with the default configura ...

Show More