A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://access.redhat.com/security/cve/CVE-2024-3508 | Vendor Advisory |
https://access.redhat.com/security/cve/CVE-2024-3508 | Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2274109 | Issue Tracking Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=2274109 | Issue Tracking Vendor Advisory |
Configurations
History
18 Jun 2025, 19:28
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:redhat:trusted_profile_analyzer:-:*:*:*:*:*:*:* | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2274109 - Issue Tracking, Vendor Advisory | |
References | () https://access.redhat.com/security/cve/CVE-2024-3508 - Vendor Advisory | |
First Time |
Redhat
Redhat trusted Profile Analyzer |
|
CWE | CWE-434 |
16 Oct 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-434 CWE-400 |
25 Apr 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-25 18:15
Updated : 2025-06-18 19:28
NVD link : CVE-2024-3508
Mitre link : CVE-2024-3508
JSON object : View
Products Affected
redhat
- trusted_profile_analyzer
CWE
No CWE.