Denial of Service Vulnerability in Aim Web API by Aimhubio
CVE-2024-12778
7.5HIGH
What is CVE-2024-12778?
A vulnerability in Aimhubio's Aim version 3.25.0 exposes the web server to denial of service attacks. This issue occurs when an excessive number of metrics are requested simultaneously from the Aim web API, overwhelming the server and rendering it unresponsive. The vulnerability stems from the absence of restrictions on the number of metrics retrievable in a single API call, coupled with the server's single-threaded design, resulting in high resource consumption and potential service outages.
Affected Version(s)
aimhubio/aim <= unspecified