A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-50235 A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 17 Oct 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Cert
Cert vince
CPEs cpe:2.3:a:cert:vince:*:*:*:*:*:*:*:*
Vendors & Products Cert
Cert vince
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}


Tue, 15 Oct 2024 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Description A Potential DOS Vulnerability exists in CERT VINCE software prior to version 3.0.8. An authenticated administrative user can inject an arbitrary pickle object as part of a user's profile. This can lead to a potential DoS on the server when the user's profile is accessed. Django server does restrict unpickling from crashing the server. A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations.
Title A Potential DOS Vulnerability exists in CERT software prior to version 3.0.8 Potential DoS Vulnerability in CERT VINCE Software Before Version 3.0.8

Mon, 14 Oct 2024 21:30:00 +0000

Type Values Removed Values Added
Description A Potential DOS Vulnerability exists in CERT VINCE software prior to version 3.0.8. An authenticated administrative user can inject an arbitrary pickle object as part of a user's profile. This can lead to a potential DoS on the server when the user's profile is accessed. Django server does restrict unpickling from crashing the server.
Title A Potential DOS Vulnerability exists in CERT software prior to version 3.0.8
Weaknesses CWE-502
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2025-03-20T18:58:47.620Z

Reserved: 2024-10-14T20:49:18.194Z

Link: CVE-2024-9953

cve-icon Vulnrichment

Updated: 2024-10-15T15:41:19.123Z

cve-icon NVD

Status : Modified

Published: 2024-10-14T22:15:03.957

Modified: 2025-03-20T19:15:36.063

Link: CVE-2024-9953

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.