Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. Giskard versions prior to 2.15.5 are affected.
CVSS
No CVSS.
References
Configurations
No configuration.
History
18 Nov 2024, 21:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 0.0 |
15 Nov 2024, 13:58
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
14 Nov 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-14 18:15
Updated : 2024-11-18 21:35
NVD link : CVE-2024-52524
Mitre link : CVE-2024-52524
CVE.ORG link : CVE-2024-52524
JSON object : View
Products Affected
No product.
CWE
CWE-1333
Inefficient Regular Expression Complexity