CVE-2024-8061
HIGHaim 3.23.0 - Denial of Service via Timeout-Free External Resource Access
Title source: llmDescription
In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the `aim` tracking server to communicate with external resources, specifically in the `_run_read_instructions` method and similar calls without timeouts.
References (1)
Core 1
Core References
Exploit, Third Party Advisory
https://huntr.com/bounties/c85d005c-b354-4c51-a88f-adda2f09622b
Scores
CVSS v3
7.5
EPSS
0.0047
EPSS Percentile
64.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-1088
Status
published
Products (2)
aimstack/aim
3.23.0
pypi/aim
0PyPI
Published
Mar 20, 2025
Tracked Since
Feb 18, 2026