GHSA-5vwr-qchf-q4pf: @cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths
A command injection vulnerability existed in the Maven scanning flow of cdxgen before version 12.4.3.
When cdxgen scanned an attacker-controlled Maven project, repository-controlled paths could be used in the Maven command construction. In affected versions, some Maven invocations were executed with shell: true. A directory name containing shell metacharacters could therefore be interpreted by the shell instead of being treated only as a filesystem path.
This could allow an attacker who controls a scanned repository to execute commands in the cdxgen process context.
The issue affected both the CLI and server mode. The issue is patched in 12.4.3.
References
Code Behaviors & Features
Detect and mitigate GHSA-5vwr-qchf-q4pf with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →