Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hxf3-vgpm-fv9p | CycloneDX cdxgen may execute code contained within build-related files |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Wed, 30 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cyclonedx
Cyclonedx cdxgen |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:cyclonedx:cdxgen:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cyclonedx
Cyclonedx cdxgen |
|
| Metrics |
cvssV3_1
|
Sun, 27 Oct 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a design limitation, rather than an implementation mistake. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-30T18:25:27.344Z
Reserved: 2024-10-27T00:00:00.000Z
Link: CVE-2024-50611
Updated: 2024-10-30T18:25:21.544Z
Status : Deferred
Published: 2024-10-27T22:15:03.557
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-50611
No data.
OpenCVE Enrichment
No data.
Github GHSA