Dismissed
Permalink
CVE-2024-3508
4.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): None (N)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): Low (L)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
9 packages
- bzip2
- lbzip2
- pbzip2
- bzip2_1_1
- indexed-bzip2
- haskellPackages.bzip2-clib
- python312Packages.indexed-bzip2
- python313Packages.indexed-bzip2
- tests.pkg-config.defaultPkgConfigPackages.bzip2
- @LeSuisse dismissed
Bzip2: compressed content bomb leads to denial of service of bombastic api
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.
References
Affected products
bzip2
- ==faa7a496c5d98e0f0859dd2c623eddf82289eaa8
SBOM-Management-(Bombastic)
Ignored packages (9)
pkgs.pbzip2
Parallel implementation of bzip2 for multi-core machines
-
nixos-unstable -
- nixpkgs-unstable 1.1.13
pkgs.bzip2_1_1
High-quality data compression program
-
nixos-unstable -
- nixpkgs-unstable 2020-08-11
pkgs.indexed-bzip2
Python library for parallel decompression and seeking within compressed bzip2 files
-
nixos-unstable -
- nixpkgs-unstable 1.6.0
pkgs.haskellPackages.bzip2-clib
bzip2 C sources
-
nixos-unstable -
- nixpkgs-unstable 1.0.8
pkgs.python312Packages.indexed-bzip2
Python library for parallel decompression and seeking within compressed bzip2 files
-
nixos-unstable -
- nixpkgs-unstable indexed_bzip2-1.6.0
pkgs.python313Packages.indexed-bzip2
Python library for parallel decompression and seeking within compressed bzip2 files
-
nixos-unstable -
- nixpkgs-unstable indexed_bzip2-1.6.0
pkgs.tests.pkg-config.defaultPkgConfigPackages.bzip2
Test whether bzip2-1.0.8 exposes pkg-config modules bzip2
-
nixos-unstable -
- nixpkgs-unstable bzip2