An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
References
Link | Resource |
---|---|
https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users | Release Notes Vendor Advisory |
Configurations
History
08 Apr 2025, 20:06
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:snowplow:iglu_server:*:*:*:*:*:*:*:* | |
First Time |
Snowplow
Snowplow iglu Server |
|
References | () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - Release Notes, Vendor Advisory |
04 Apr 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
Summary |
|
|
CWE | CWE-400 |
03 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-03 21:15
Updated : 2025-04-08 20:06
NVD link : CVE-2024-47212
Mitre link : CVE-2024-47212
CVE.ORG link : CVE-2024-47212
JSON object : View
Products Affected
snowplow
- iglu_server
CWE
CWE-400
Uncontrolled Resource Consumption