Skip to content
Noroxi

async project records

2 published records for vendor async project.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

2 records
  • In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js

    HighCVSS 7.8No exploitEPSS 3%

    async project · asyncApr 6, 2022

  • Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function.

    HighCVSS 7.5No exploitEPSS 1%

    Jul 1, 2024