github.com
https://github.com/aimeos/aimeos-core CVE-2024-37294
MEDIUM
Aimeos denial of service vulnerability in SaaS and marketplace setups
Record summary
CVE-2024-37294 has a selected CVSS score of 5.5 (medium).
Description
Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users should upgrade to versions 2022.10.17, 2023.10.17, or 2024.04 of the aimeos/aimeos-core package to receive a patch.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 11, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
aimeos-coreBrowse aimeos / aimeos-coreDefault status: unknown | CVE List | Before 2024.04.7 | affected |
| Before 2023.10.17 | affected | ||
| Before 2022.10.17 | affected | ||
| >= 2024.04.1, < 2024.04.7 | affected | ||
| >= 2023.04.1, < 2023.10.17 | affected | ||
| >= 2022.04.1, < 2022.10.17 | affected | ||
aimeos/aimeos-coreBrowse Packagist / aimeos/aimeos-core | GitHub Advisory | 2024.04.1 to < 2024.04.7 · Fixed in 2024.04.7 | affected |
| 2023.04.1 to < 2023.10.17 · Fixed in 2023.10.17 | affected | ||
| 2022.04.1 to < 2022.10.17 · Fixed in 2022.10.17 | affected |
References
9github.com
https://github.com/aimeos/aimeos-core/commit/66edb06a53e51d90e075aad1932811c53c40af6f github.com
https://github.com/aimeos/aimeos-core/commit/69e2ea127c4e2fd2e756a80a16442bea0351a461 github.com
https://github.com/aimeos/aimeos-core/commit/e933345915fc0cfafc6a011b853bc0228a61a45f github.com
https://github.com/aimeos/aimeos-core/compare/2022.10.16...2022.10.17 github.com
https://github.com/aimeos/aimeos-core/compare/2023.10.16...2023.10.17 github.com
https://github.com/aimeos/aimeos-core/compare/2024.04.6...2024.04.7 github.comConfirmation
https://github.com/aimeos/aimeos-core/security/advisories/GHSA-xjm6-jfmg-qc6p nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-37294