GHSA-xjm6-jfmg-qc6p

Suggest an improvement
Source
https://github.com/advisories/GHSA-xjm6-jfmg-qc6p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-xjm6-jfmg-qc6p/GHSA-xjm6-jfmg-qc6p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xjm6-jfmg-qc6p
Aliases
  • CVE-2024-37294
Published
2024-05-29T14:38:11Z
Modified
2024-06-11T21:14:02.207949Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
Aimeos denial of service vulnerability in SaaS and marketplace setups
Details

Impact

All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack

Patches

Upgrade to the latest 2022.10 LTS, 2023.10 LTS and 2024.04.7 version of the aimeos/aimeos-core package

Database specific
{
    "nvd_published_at": "2024-06-11T15:16:09Z",
    "cwe_ids": [
        "CWE-270"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-29T14:38:11Z"
}
References

Affected packages

Packagist / aimeos/aimeos-core

Package

Name
aimeos/aimeos-core
Purl
pkg:composer/aimeos/aimeos-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2024.04.1
Fixed
2024.04.7

Affected versions

2024.*

2024.04.1
2024.04.2
2024.04.3
2024.04.4
2024.04.5
2024.04.6

Packagist / aimeos/aimeos-core

Package

Name
aimeos/aimeos-core
Purl
pkg:composer/aimeos/aimeos-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2023.04.1
Fixed
2023.10.17

Affected versions

2023.*

2023.04.1
2023.04.2
2023.04.3
2023.04.4
2023.04.5
2023.04.6
2023.07.1
2023.07.2
2023.07.3
2023.10.1
2023.10.2
2023.10.3
2023.10.4
2023.10.5
2023.10.6
2023.10.7
2023.10.8
2023.10.9
2023.10.10
2023.10.11
2023.10.12
2023.10.13
2023.10.14
2023.10.15
2023.10.16

Packagist / aimeos/aimeos-core

Package

Name
aimeos/aimeos-core
Purl
pkg:composer/aimeos/aimeos-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2022.04.1
Fixed
2022.10.17

Affected versions

2022.*

2022.04.1
2022.04.2
2022.04.3
2022.04.4
2022.04.5
2022.04.6
2022.04.7
2022.04.8
2022.04.9
2022.04.10
2022.07.1
2022.07.2
2022.07.3
2022.07.4
2022.07.5
2022.07.6
2022.07.7
2022.07.8
2022.10.1
2022.10.2
2022.10.3
2022.10.4
2022.10.5
2022.10.6
2022.10.7
2022.10.8
2022.10.9
2022.10.10
2022.10.11
2022.10.12
2022.10.13
2022.10.14
2022.10.15
2022.10.16