CVE-2024-37294: Aimeos denial of service vulnerability in SaaS and marketplace setups
(updated )
All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack
References
- github.com/advisories/GHSA-xjm6-jfmg-qc6p
- github.com/aimeos/aimeos-core
- github.com/aimeos/aimeos-core/commit/66edb06a53e51d90e075aad1932811c53c40af6f
- github.com/aimeos/aimeos-core/commit/69e2ea127c4e2fd2e756a80a16442bea0351a461
- github.com/aimeos/aimeos-core/commit/e933345915fc0cfafc6a011b853bc0228a61a45f
- github.com/aimeos/aimeos-core/compare/2022.10.16...2022.10.17
- github.com/aimeos/aimeos-core/compare/2023.10.16...2023.10.17
- github.com/aimeos/aimeos-core/compare/2024.04.6...2024.04.7
- github.com/aimeos/aimeos-core/security/advisories/GHSA-xjm6-jfmg-qc6p
- nvd.nist.gov/vuln/detail/CVE-2024-37294
Detect and mitigate CVE-2024-37294 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →