CVE-2024-52524

Giskard is an evaluation and testing framework for AI systems. A Remote Code Execution (ReDoS) vulnerability was discovered in Giskard component by the GitHub Security Lab team. When processing datasets with specific text patterns with Giskard detectors, this vulnerability could trigger exponential regex evaluation times, potentially leading to denial of service. Giskard versions prior to 2.15.5 are affected.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2024-11-14 18:15

Updated : 2024-11-21 15:15


NVD link : CVE-2024-52524

Mitre link : CVE-2024-52524

CVE.ORG link : CVE-2024-52524


JSON object : View

Products Affected

No product.

CWE
CWE-1333

Inefficient Regular Expression Complexity