CVE-2024-12777CWE-1088

Denial of Service in aimhubio/aim

Medium · published March 20, 2025

CVSS v3.0
5.9
EPSS
0%
Percentile
38.6
In the wild
Unconfirmed
What it is

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests.

The record
Technical detail
CVSS v3.0
5.9 · MEDIUM
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.00465 · 38.6th percentile
Weakness
CWE-1088 · Synchronous Access of Remote Resource without Timeout
Published
2025-03-20T10:11Z
EPSS history
Timeline
  • 20 MAR 10:11Z
    Denial of Service in aimhubio/aim
    cvelistv5