CVE-2024-12778

CVSS 3.0 Score 7.5 of 10 (high)

Details

Published Mar 20, 2025
CWE ID 400

Summary

CVE-2024-12778 is a denial-of-service vulnerability affecting aimhubio/aim version 3.25.0. The issue occurs when the Aim web API is bombarded with a large number of metric requests, causing the web server to become unresponsive. This vulnerability stems from the lack of a limit on the number of metrics that can be requested per call and the server's single-threaded nature, resulting in excessive resource consumption and eventual server blocking. Attackers can exploit this vulnerability to launch a denial-of-service attack, rendering the server unavailable to legitimate users.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share