CVE-2024-56528

This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data would not enter the pipeline and would be potentially lost.
Configurations

Configuration 1 (hide)

cpe:2.3:a:snowplow:stream_collector:*:*:*:*:*:*:*:*

History

15 Apr 2025, 19:29

Type Values Removed Values Added
CPE cpe:2.3:a:snowplow:stream_collector:*:*:*:*:*:*:*:*
First Time Snowplow
Snowplow stream Collector
References () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - () https://support.snowplow.io/hc/en-us/articles/26318139354909-Update-Critical-Snowplow-Security-Updates-Impact-on-Open-Source-Software-Users - Release Notes, Patch

07 Apr 2025, 19:15

Type Values Removed Values Added
CWE CWE-400
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

07 Apr 2025, 14:18

Type Values Removed Values Added
Summary
  • (es) Esta vulnerabilidad afecta a Snowplow Collector 3.x anterior a la 3.3.0 (a menos que esté configurado tras un proxy inverso que limite el payload). Implica el envío de payloads muy grandes al Collector, lo que puede impedir que responda al resto de las solicitudes. Como resultado, los datos no entrarían en la canalización y podrían perderse.

03 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-03 21:15

Updated : 2025-04-15 19:29


NVD link : CVE-2024-56528

Mitre link : CVE-2024-56528

CVE.ORG link : CVE-2024-56528


JSON object : View

Products Affected

snowplow

  • stream_collector
CWE
CWE-400

Uncontrolled Resource Consumption