Aimhubio's Aim Vulnerable to Cross-Site Request Forgery (CSRF) Attacks
CVE-2024-2196
What is CVE-2024-2196?
The Aimhubio Aim product has a significant vulnerability that exposes the system to Cross-Site Request Forgery (CSRF) attacks. This flaw permits malicious actors to perform unauthorized actions on behalf of users, including the deletion of important runs, unauthorized updates to critical data, and the theft of sensitive information such as log records and notes. The root cause of this vulnerability lies in the inadequate CSRF and CORS protections within the aim dashboard. Attackers can exploit this weakness by luring users into executing harmful scripts, which trigger unauthorized requests to the aim server. Such actions can lead to severe consequences, including data loss and unauthorized modifications of user data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
aimhubio/aim <= unspecified
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
