Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-52524

Опубликовано: 14 нояб. 2024
Источник: nvd
EPSS Низкий

Описание

Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. Giskard versions prior to 2.15.5 are affected.

EPSS

Процентиль: 81%
0.01477
Низкий

Дефекты

CWE-1333

Связанные уязвимости

github
около 1 года назад

ReDoS in giskard's transformation.py (GHSL-2024-324)

EPSS

Процентиль: 81%
0.01477
Низкий

Дефекты

CWE-1333