Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in file size than the original. This vulnerability is fixed in 11.2.4.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-06-04T14:43:20.796Z

Updated: 2024-08-02T02:20:35.642Z

Reserved: 2024-04-19T14:07:11.229Z

Link: CVE-2024-32871

cve-icon Vulnrichment

Updated: 2024-06-04T15:28:32.084Z

cve-icon NVD

Status : Analyzed

Published: 2024-06-04T15:15:45.757

Modified: 2024-06-10T21:07:12.030

Link: CVE-2024-32871

cve-icon Redhat

No data.