First published: Mon Jul 01 2024(Updated: )
Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function.
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Data Virtualization on Cloud Pak for Data | <=2.6.4<=3.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2295035 is categorized as a ReDoS, which can lead to denial of service.
To fix REDHAT-BUG-2295035, update your Async library to a version greater than 3.2.5.
REDHAT-BUG-2295035 affects Async versions up to and including 2.6.4 and 3.2.5.
REDHAT-BUG-2295035 is a Regular Expression Denial of Service (ReDoS) vulnerability.
REDHAT-BUG-2295035 impacts the parsing functions within the autoinject function in the Async library.