PT-2024-29418 · Lunary · Lunary

Published

2024-06-01

·

Updated

2025-01-30

·

CVE-2024-4148

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lunary-ai/lunary version 1.2.10
Description A Regular Expression Denial of Service (ReDoS) issue exists, allowing an attacker to significantly impact the application's response time and potentially render it non-functional by manipulating regular expressions. This can be triggered by sending a specially crafted request to the application, leading to a denial of service where the application crashes.
Recommendations For version 1.2.10, consider restricting the use of regular expressions in the application until a patch is available. As a temporary workaround, review and limit the input that can be used to trigger the ReDoS vulnerability.

Exploit

Fix

Resource Exhaustion

DoS

Weakness Enumeration

Related Identifiers

CVE-2024-4148

Affected Products

Lunary