HIGH
Denial of Service in aimhubio/aim
Published Mar 20, 2025
7.5
HIGHCVSS 3.0
EPSS 0.63%
Description
In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial of service as the tracking server becomes unable to respond to other requests.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=latest
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Aimhubio | Aimhubio/aim | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://github.com/advisories/GHSA-fx47-jpv9-7hxr Advisory
- https://github.com/aimhubio/aim/blob/a566d4a2501c96a545a3c89d92af6ad7e7e0da99/aim/sdk/reporter/__init__.py#L789
- https://huntr.com/bounties/5ea6cf56-7b4c-4dce-9b6c-3e910fbb1ae4 ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-10110
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Mar 20, 2025
Updated Mar 20, 2025
Reserved Oct 17, 2024
Link CVE-2024-10110
CISA Vulnrichment
GHSA-FX47-JPV9-7HXR Updated Mar 20, 2025