REDHAT-BUG-2295035: Medium severity Async Async vulnerability
Published Jul 1, 2024
·Updated
Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function.
Affected Software
1 affected component
Async Async<=2.6.4, <=3.2.5
Event History
Jul 1, 2024
Data Sourced
via Red Hat·08:20 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2295035?
The severity of REDHAT-BUG-2295035 is categorized as a ReDoS, which can lead to denial of service.
2
How do I fix REDHAT-BUG-2295035?
To fix REDHAT-BUG-2295035, update your Async library to a version greater than 3.2.5.
3
Which versions are affected by REDHAT-BUG-2295035?
REDHAT-BUG-2295035 affects Async versions up to and including 2.6.4 and 3.2.5.
4
What type of vulnerability is REDHAT-BUG-2295035?
REDHAT-BUG-2295035 is a Regular Expression Denial of Service (ReDoS) vulnerability.
5
What does REDHAT-BUG-2295035 impact?
REDHAT-BUG-2295035 impacts the parsing functions within the autoinject function in the Async library.