CVE-2024-31380

Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.
Configurations

No configuration.

History

26 Aug 2024, 08:15

Type Values Removed Values Added
Summary (en) Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection.This issue affects Oxygen Builder: from n/a through 4.8.3. (en) Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.

05 Jun 2024, 11:15

Type Values Removed Values Added
Summary (en) Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection.This issue affects Oxygen Builder: from n/a through 4.8.2. (en) Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection.This issue affects Oxygen Builder: from n/a through 4.8.3.
References
  • () https://snicco.io/vulnerability-disclosure/oxygen/client-control-remote-code-execution-oxygen-4-8-1 -

25 Apr 2024, 09:15

Type Values Removed Values Added
References
  • {'url': 'https://patchstack.com/articles/unpatched-authenticated-rce-in-oxygen-and-breakdance-builder?_s_id=cve', 'source': 'audit@patchstack.com'}
  • {'url': 'https://snicco.io/vulnerability-disclosure/oxygen/client-control-remote-code-execution-oxygen-4-8-1?_s_id=cve', 'source': 'audit@patchstack.com'}

05 Apr 2024, 14:15

Type Values Removed Values Added
References
  • () https://patchstack.com/articles/unpatched-authenticated-rce-in-oxygen-and-breakdance-builder?_s_id=cve -
Summary
  • (es) La vulnerabilidad de control inadecuado de la generación de código ("inyección de código") en Soflyy Oxygen Builder permite la inyección de código. Este problema afecta a Oxygen Builder: desde n/a hasta 4.8.2.

03 Apr 2024, 18:15

Type Values Removed Values Added
Summary (en) Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection.This issue affects Oxygen Builder: from n/a through 4.8.1. (en) Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection.This issue affects Oxygen Builder: from n/a through 4.8.2.

03 Apr 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-03 12:15

Updated : 2024-08-26 08:15


NVD link : CVE-2024-31380

Mitre link : CVE-2024-31380

CVE.ORG link : CVE-2024-31380


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')