github.com
https://github.com/aimeos/ai-admin-graphql CVE-2024-47173
MEDIUM
Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups
Record summary
CVE-2024-47173 has a selected CVSS score of 5.5 (medium).
Description
Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 24, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ai-admin-graphqlBrowse aimeos / ai-admin-graphql | CVE List | >= 2024.04.1, < 2024.07.2 | affected |
aimeos/ai-admin-graphqlBrowse Packagist / aimeos/ai-admin-graphql | GitHub Advisory | 2024.04.1 to < 2024.07.2 · Fixed in 2024.07.2 | affected |
References
3github.comConfirmation
https://github.com/aimeos/ai-admin-graphql/security/advisories/GHSA-qxgx-hvg3-v92w nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-47173