Логотип exploitDog
bind:CVE-2021-41167
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-41167

Количество 2

Количество 2

nvd логотип

CVE-2021-41167

больше 4 лет назад

modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but, in practice, they don't. Any code calling these functions will be written thinking they would limit the concurrency but they won't. This could lead to potential security issues in other projects. The problem has been patched in 1.0.4. There is no workaround.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3pcq-34w5-p4g2

больше 4 лет назад

modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-41167

modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but, in practice, they don't. Any code calling these functions will be written thinking they would limit the concurrency but they won't. This could lead to potential security issues in other projects. The problem has been patched in 1.0.4. There is no workaround.

CVSS3: 7.5
0%
Низкий
больше 4 лет назад
github логотип
GHSA-3pcq-34w5-p4g2

modern-async's `forEachSeries` and `forEachLimit` functions do not limit the number of requests

CVSS3: 7.5
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу