An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
References
Link | Resource |
---|---|
https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users | Release Notes Vendor Advisory |
Configurations
History
10 Apr 2025, 13:51
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-noinfo | |
References | () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - Release Notes, Vendor Advisory | |
First Time |
Snowplow
Snowplow iglu Server |
|
CPE | cpe:2.3:a:snowplow:iglu_server:*:*:*:*:*:*:*:* |
07 Apr 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
07 Apr 2025, 14:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-03 21:15
Updated : 2025-04-10 13:51
NVD link : CVE-2024-47214
Mitre link : CVE-2024-47214
CVE.ORG link : CVE-2024-47214
JSON object : View
Products Affected
snowplow
- iglu_server
CWE