CVE-2024-45338

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Dec 18, 2024
Updated: Dec 31, 2024
CWE ID 1333

Summary

CVE-2024-45338 is a newly disclosed cybersecurity vulnerability that affects Parse functions. An attacker can manipulate inputs to these functions, leading to non-linear processing with regard to input length. This irregular parsing results in a significant slowdown, potentially culminating in a denial-of-service attack. The vulnerability lies in the way the Parse functions handle input, allowing an adversary to exploit the system's resources and cause performance degradation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share