Description

fugit contains time tools for flor and the floraison group. The fugit "natural" parser, that turns "every wednesday at 5pm" into "0 17 * * 3", accepted any length of input and went on attempting to parse it, not returning promptly, as expected. The parse call could hold the thread with no end in sight. Fugit dependents that do not check (user) input length for plausibility are impacted. A fix was released in fugit 1.11.1.

INFO

Published Date :

2024-08-19T14:37:39.532Z

Last Modified :

2024-09-03T15:03:00.904Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-43380 vulnerability.

Vendors Products
Floraison
  • Fugit

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact