CVE-2024-12778
CVSS 3.0 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-12778 is a denial-of-service vulnerability affecting aimhubio/aim version 3.25.0. The issue occurs when the Aim web API is bombarded with a large number of metric requests, causing the web server to become unresponsive. This vulnerability stems from the lack of a limit on the number of metrics that can be requested per call and the server's single-threaded nature, resulting in excessive resource consumption and eventual server blocking. Attackers can exploit this vulnerability to launch a denial-of-service attack, rendering the server unavailable to legitimate users.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Aim