CVE-2024-32871

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-32871
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-32871.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-32871
Aliases
Published
2024-06-04T14:43:20.796Z
Modified
2025-12-05T04:20:20.509075Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Pimcore Vulnerable to Flooding Server with Thumbnail files
Details

Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in file size than the original. This vulnerability is fixed in 11.2.4.

Database specific
{
    "cwe_ids": [
        "CWE-770"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32871.json"
}
References

Affected packages

Git / github.com/pimcore/pimcore

Affected ranges

Type
GIT
Repo
https://github.com/pimcore/pimcore
Events

Affected versions

v10.*

v10.5.24
v10.5.25
v10.6.1
v10.6.2
v10.6.3
v10.6.4
v10.6.5
v10.6.6
v10.6.7
v10.6.8
v10.6.9

v11.*

v11.0.0
v11.0.1
v11.0.10
v11.0.11
v11.0.12
v11.0.2
v11.0.3
v11.0.4
v11.0.5
v11.0.6
v11.0.7
v11.0.8
v11.0.9
v11.1.0
v11.1.0-RC1
v11.1.1
v11.1.2
v11.1.3
v11.1.4
v11.1.5
v11.1.6
v11.2.0
v11.2.1
v11.2.2
v11.2.3