CVE-2024-47173

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-47173
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-47173.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-47173
Aliases
Published
2024-10-24T18:54:12.478Z
Modified
2025-12-05T06:32:40.474809Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups
Details

Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue.

Database specific
{
    "cwe_ids": [
        "CWE-270"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47173.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/aimeos/ai-admin-graphql

Affected ranges

Type
GIT
Repo
https://github.com/aimeos/ai-admin-graphql
Events
Database specific
{
    "versions": [
        {
            "introduced": "2024.04.1"
        },
        {
            "fixed": "2024.07.2"
        }
    ]
}