Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-4148

Опубликовано: 01 июн. 2024
Источник: nvd
CVSS3: 7.5
CVSS3: 7.5
EPSS Низкий

Описание

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular expressions, which can significantly impact the response time of the application and potentially render it completely non-functional. Specifically, the vulnerability can be triggered by sending a specially crafted request to the application, leading to a denial of service where the application crashes.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:lunary:lunary:1.2.10:*:*:*:*:*:*:*

EPSS

Процентиль: 27%
0.00096
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-1333

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular expressions, which can significantly impact the response time of the application and potentially render it completely non-functional. Specifically, the vulnerability can be triggered by sending a specially crafted request to the application, leading to a denial of service where the application crashes.

EPSS

Процентиль: 27%
0.00096
Низкий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-1333
CWE-1333