CVE-2024-47215

An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throughput).
Configurations

Configuration 1 (hide)

cpe:2.3:a:snowplow:snowbridge:-:*:*:*:*:*:*:*

History

23 Apr 2025, 14:55

Type Values Removed Values Added
CPE cpe:2.3:a:snowplow:snowbridge:-:*:*:*:*:*:*:*
First Time Snowplow snowbridge
Snowplow
References () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - Patch, Vendor Advisory

07 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-703

07 Apr 2025, 14:18

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en las configuraciones de Snowbridge que envían datos al servidor de Google Tag Manager. Este problema implica adjuntar un encabezado de vista previa de GTM SS no válido a los eventos, lo que provoca que se reintenten indefinidamente. Como resultado, el rendimiento general del reenvío de eventos a GTM SS puede verse afectado (latencia y rendimiento).

03 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-03 21:15

Updated : 2025-04-23 14:55


NVD link : CVE-2024-47215

Mitre link : CVE-2024-47215

CVE.ORG link : CVE-2024-47215


JSON object : View

Products Affected

snowplow

  • snowbridge
CWE
CWE-703

Improper Check or Handling of Exceptional Conditions