Intel

AIKIDO-2024-10053

prefect is vulnerable to Regular Expression Denial of Service (ReDoS)

Regular Expression Denial of Service (ReDoS)CVE-2024-24762 Published Apr 24, 2024

52

Medium Risk

This Affects:

pythonprefect
2.14.0 - 2.14.21
Fixed in 2.15.0
Are you affected? Scan for Free

TL;DR

Due to a vulnerability in the starlette package (CVE-2024-24762) and the inability of Prefect to update to a fixed version, parts of the package were rewritten to eliminate the vulnerability. Affected versions of this package are susceptible to regular expression Denial of Service (ReDoS) in python-multipart.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

prefect is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 2.14.0 - 2.14.21.

How to fix this

Upgrade the prefect library to the patch version.