A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.
The product does not properly control the allocation and maintenance of a limited resource.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2024-3508 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2274109 | issue tracking |