async project records
2 published records for vendor async project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-1333 Inefficient Regular Expression Complexity1
The weakness classes this vendor ships most often: where to look.
CWEAll records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2021-43138No exploit | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js async project · async · CWE-1321 | High7.8 | — | 3.3% | Apr 6, 2022 |
30Monitor | CVE-2024-39249No exploit | Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function.CWE-1333 | High7.5 | — | 0.8% | Jul 1, 2024 |
- CVE-2021-4313832Monitor
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js
HighCVSS 7.8No exploitEPSS 3%async project · asyncApr 6, 2022
- CVE-2024-3924930Monitor
Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function.
HighCVSS 7.5No exploitEPSS 1%Jul 1, 2024