CVE-2024-8061
HIGHDescription
In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the `aim` tracking server to communicate with external resources, specifically in the `_run_read_instructions` method and similar calls without timeouts.
Is your site exposed to CVE-2024-8061?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| aimstack | aim |
References
Frequently Asked Questions
What is CVE-2024-8061? +
How severe is CVE-2024-8061? +
What products are affected by CVE-2024-8061? +
How do I check if I'm vulnerable to CVE-2024-8061? +
Related Vulnerabilities
A vulnerability in the typeahead endpoint of h2oai/h2o-3 version 3.46.0 allows for a denial of service. The endpoint performs a …
A network-reachable client that has not yet authenticated can hold a MongoDB Connector for BI authentication session open indefinitely by …
Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in the SMUX module where smux_accept() performs an unauthenticated blocking read …
A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking …
Vault Community and Vault Enterprise rekey and recovery key operations can lead to a denial of service due to uncontrolled …
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions …