In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the server to become unresponsive to other requests while processing the large image, leading to a denial of service condition.
History

Fri, 28 Mar 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Aimstack
Aimstack aim
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:aimstack:aim:3.25.0:*:*:*:*:*:*:*
Vendors & Products Aimstack
Aimstack aim
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description In version 3.25.0 of aimhubio/aim, the tracking server is vulnerable to a denial of service attack. The server overrides the maximum size for websocket messages, allowing very large images to be tracked. This causes the server to become unresponsive to other requests while processing the large image, leading to a denial of service condition.
Title Denial of Service in aimhubio/aim
Weaknesses CWE-400
References
Metrics cvssV3_0

{'score': 7.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-03-20T18:15:11.957Z

Reserved: 2025-01-03T01:24:52.404Z

Link: CVE-2025-0189

cve-icon Vulnrichment

Updated: 2025-03-20T17:50:26.195Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-20T10:15:51.660

Modified: 2025-03-28T14:31:37.077

Link: CVE-2025-0189

cve-icon Redhat

No data.