Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-38r9-3j52-h92v

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Aim vulnerable to Cross-Site Request Forgery

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write.

Пакеты

Наименование

aim

pip
Затронутые версииВерсия исправления

<= 3.22.0

Отсутствует

EPSS

Процентиль: 22%
0.0007
Низкий

7.4 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 9.6
nvd
11 месяцев назад

aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on all endpoints of the tracking server, which can be chained with other existing vulnerabilities such as remote code execution, denial of service, and arbitrary file read/write.

EPSS

Процентиль: 22%
0.0007
Низкий

7.4 High

CVSS3

Дефекты

CWE-352