CVE-2024-7779: ReDoS (Regular Expression Denial of Service) in danswer-ai/danswer
A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) by manipulating regular expressions. This can significantly slow down the application's response time and potentially render it completely unusable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7779?
CVE-2024-7779 has a high severity level as it allows for a Regular Expression Denial of Service (ReDoS).
How do I fix CVE-2024-7779?
To fix CVE-2024-7779, update to the latest version of danswer-ai/danswer that includes a patch addressing the vulnerability.
What impact does CVE-2024-7779 have on the application?
CVE-2024-7779 can significantly degrade application performance and potentially cause application downtime due to slow response times.
Who is affected by CVE-2024-7779?
Any users or organizations utilizing danswer-ai/danswer version 1 are affected by CVE-2024-7779.
Can CVE-2024-7779 be exploited remotely?
Yes, CVE-2024-7779 can be exploited remotely by an attacker manipulating regular expressions in the application.