async project kayıtları
async project üreticisine ait 2 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')1
- CWE-1333 Inefficient Regular Expression Complexity1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
2 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2021-43138İstismar yok | In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js async project · async · CWE-1321 | Yüksek7,8 | — | %3,3 | 6 Nis 2022 |
30İzleyin | CVE-2024-39249İstismar yok | Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function.CWE-1333 | Yüksek7,5 | — | %0,8 | 1 Tem 2024 |
- CVE-2021-4313832İzleyin
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js
YüksekCVSS 7,8İstismar yokEPSS %3async project · async6 Nis 2022
- CVE-2024-3924930İzleyin
Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function.
YüksekCVSS 7,5İstismar yokEPSS %11 Tem 2024