We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-12777

Denial of Service in aimhubio/aim



Description

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests.

Reserved 2024-12-18 | Published 2025-03-20 | Updated 2025-03-20 | Assigner @huntr_ai


MEDIUM: 5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-1088 Synchronous Access of Remote Resource without Timeout

Product status

Any version
affected

References

huntr.com/bounties/cdf8db79-c290-4fe5-9383-4c518bfba4a8

cve.org (CVE-2024-12777)

nvd.nist.gov (CVE-2024-12777)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2024-12777

Support options

Helpdesk Chat, Email, Knowledgebase