Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3123 | Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue. |
Github GHSA |
GHSA-qxgx-hvg3-v92w | ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Oct 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue. | |
| Title | Aimeos GraphQL API admin interface denial of service vulnerability in SaaS and marketplace setups | |
| Weaknesses | CWE-270 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-24T20:00:27.605Z
Reserved: 2024-09-19T22:32:11.961Z
Link: CVE-2024-47173
Updated: 2024-10-24T20:00:21.897Z
Status : Awaiting Analysis
Published: 2024-10-24T19:15:14.817
Modified: 2024-10-25T12:56:07.750
Link: CVE-2024-47173
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:57Z
EUVD
Github GHSA