CVE-2024-6227

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself, rendering it unable to respond to other connections.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aimstack:aim:3.19.3:*:*:*:*:*:*:*

History

30 Aug 2024, 16:15

Type Values Removed Values Added
Summary A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause a denial of service by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself, rendering it unable to respond to other connections. A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself, rendering it unable to respond to other connections.

07 Aug 2024, 12:26

Type Values Removed Values Added
CPE cpe:2.3:a:aimstack:aim:3.19.3:*:*:*:*:*:*:*
References () https://huntr.com/bounties/abcea7c6-bb3b-45e9-aa15-9eb6b224451a - () https://huntr.com/bounties/abcea7c6-bb3b-45e9-aa15-9eb6b224451a - Exploit
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Aimstack
Aimstack aim
CWE CWE-400 CWE-835

08 Jul 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-08 19:15

Updated : 2024-08-30 16:15


NVD link : CVE-2024-6227

Mitre link : CVE-2024-6227


JSON object : View

Products Affected

aimstack

  • aim
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')