CVE-2024-47213

An issue was discovered affecting Enrich 5.1.0 and below. It involves sending a maliciously crafted Snowplow event to the pipeline. Upon receiving this event and trying to validate it, Enrich crashes and attempts to restart indefinitely. As a result, event processing would be halted.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snowplow:enrich:*:*:*:*:*:*:*:*

History

23 Apr 2025, 14:58

Type Values Removed Values Added
First Time Snowplow
Snowplow enrich
CPE cpe:2.3:a:snowplow:enrich:*:*:*:*:*:*:*:*
References () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - Release Notes, Vendor Advisory

04 Apr 2025, 14:15

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema que afectaba a Enrich 5.1.0 y versiones anteriores. Este problema implicaba el envío de un evento Snowplow malintencionado a la canalización. Al recibir este evento e intentar validarlo, Enrich se bloqueaba e intentaba reiniciarse indefinidamente. Como resultado, se detenía el procesamiento del evento.
CWE CWE-404
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

03 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-03 21:15

Updated : 2025-04-23 14:58


NVD link : CVE-2024-47213

Mitre link : CVE-2024-47213

CVE.ORG link : CVE-2024-47213


JSON object : View

Products Affected

snowplow

  • enrich
CWE
CWE-404

Improper Resource Shutdown or Release