Denial of Service Vulnerability in Aim Web API by Aimhubio
CVE-2024-12778
7.5HIGH
Summary
A vulnerability in Aimhubio's Aim version 3.25.0 exposes the web server to denial of service attacks. This issue occurs when an excessive number of metrics are requested simultaneously from the Aim web API, overwhelming the server and rendering it unresponsive. The vulnerability stems from the absence of restrictions on the number of metrics retrievable in a single API call, coupled with the server's single-threaded design, resulting in high resource consumption and potential service outages.
Affected Version(s)
aimhubio/aim <= unspecified
References
CVSS V3.0
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved