Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-39249
HistoryJul 01, 2024 - 12:00 a.m.

CVE-2024-39249

2024-07-0100:00:00
ubuntu.com
ubuntu.com
6
async
vulnerable
redos
regular expression denial of service
autoinject
unix

AI Score

6.6

Confidence

Low

Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression
Denial of Service) while parsing function in autoinject function. NOTE:
this is disputed by the supplier because there is no realistic threat
model: regular expressions are not used with untrusted input.

AI Score

6.6

Confidence

Low