CVE-2024-10110High· 7.5▾ TwilightAim Vulnerable to Denial of Service (DoS)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.6%
In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial of service as the tracking server becomes unable to respond to other requests.
aim >= 3.15.0, <= 3.23.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-2195Critical· 9.8Aim Web API vulnerable to Remote Code Execution
CVE-2024-8769Critical· 9.1Aim path traversal in LockManager.release_locks
CVE-2024-12777Medium· 5.9Aim vulnerable to Synchronous Access of Remote Resource without Timeout
CVE-2024-8238Medium· 5.9Aim Improper Access Control
CVE-2024-8863Low· 3.5Aim Stored XSS through TEXT EXPLORER
CVE-2024-6578Medium· 6.1Aim Stored Cross-site Scripting Vulnerability