Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6w7p-xrvp-p7xv

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Aim allows denial of service due to no timeouts for some tracking server endpoints

In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the aim tracking server to communicate with external resources, specifically in the _run_read_instructions method and similar calls without timeouts.

Пакеты

Наименование

aim

pip
Затронутые версииВерсия исправления

<= 3.23.0

Отсутствует

EPSS

Процентиль: 28%
0.00101
Низкий

7.5 High

CVSS3

Дефекты

CWE-1088
CWE-400

Связанные уязвимости

CVSS3: 7.5
nvd
11 месяцев назад

In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the `aim` tracking server to communicate with external resources, specifically in the `_run_read_instructions` method and similar calls without timeouts.

EPSS

Процентиль: 28%
0.00101
Низкий

7.5 High

CVSS3

Дефекты

CWE-1088
CWE-400