← Back to CVE List

CVE-2024-3508

Published: 2024-04-25T18:15Z
Last Modified: 2024-11-21T09:29Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A flaw was found in Bombastic, which allows authenticated users to upload compressed (bzip2 or zstd) SBOMs. The API endpoint verifies the presence of some fields and values in the JSON. To perform this verification, the uploaded file must first be decompressed. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt