CVE-2024-47213

An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:snowplow:enrich:*:*:*:*:*:*:*:*

History

23 Apr 2025, 14:58

Type Values Removed Values Added
CPE cpe:2.3:a:snowplow:enrich:*:*:*:*:*:*:*:*
References () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-UsersĀ - () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-UsersĀ - Release Notes, Vendor Advisory
First Time Snowplow
Snowplow enrich

03 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-03 21:15

Updated : 2025-04-23 14:58


NVD link : CVE-2024-47213

Mitre link : CVE-2024-47213


JSON object : View

Products Affected

snowplow

  • enrich
CWE

No CWE.