Back to Database
Status published
High
CVE-2024-34345
@cyclonedx/cyclonedx-library Improper Restriction of XML External Entity Reference vulnerability
Vulnerability Description
The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were possible, when running the provided XML Validator on arbitrary input. This issue was fixed in version 6.7.1.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-34345
Credits & Attribution
No credits recorded in the NVD database.
References
More from CycloneDX
View All →CVE-2025-64518
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
High
7.5
CVE-2024-38374
Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java
High
7.5
CVE-2022-24774
Improper Input Validation leading to Path Traversal in CycloneDX BOM Repository Server
High
7.1
Affected Vendor
CycloneDX
View all reports →Affected Software
cyclonedx-javascript-library
Vulnerable Versions:
= 6.7.0
Timeline
Official Publish:
May 9th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H