An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
References
Link | Resource |
---|---|
https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users | Release Notes Vendor Advisory |
Configurations
History
08 Apr 2025, 18:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Snowplow
Snowplow iglu Server |
|
CPE | cpe:2.3:a:snowplow:iglu_server:*:*:*:*:*:*:*:* | |
References | () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - Release Notes, Vendor Advisory | |
CWE | NVD-CWE-noinfo |
07 Apr 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
07 Apr 2025, 14:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Apr 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-03 21:15
Updated : 2025-04-08 18:55
NVD link : CVE-2024-47217
Mitre link : CVE-2024-47217
CVE.ORG link : CVE-2024-47217
JSON object : View
Products Affected
snowplow
- iglu_server
CWE