CVE-2024-6227

HIGH

aim 3.19.3 - Denial of Service via Remote Tracking Server Loop

Title source: llm
STIX 2.1

Description

A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself, rendering it unable to respond to other connections.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0057
EPSS Percentile 42.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-835
Status published
Products (2)
aimstack/aim 3.19.3
pypi/aim 0PyPI
Published Jul 08, 2024
Tracked Since Feb 18, 2026