NA

CVE-2024-3508

Published: 25/04/2024 Updated: 26/04/2024

Vulnerability Summary

A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.