CVE-2024-8061

In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the `aim` tracking server to communicate with external resources, specifically in the `_run_read_instructions` method and similar calls without timeouts.
References
Link Resource
https://huntr.com/bounties/c85d005c-b354-4c51-a88f-adda2f09622b Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:aimstack:aim:3.23.0:*:*:*:*:python:*:*

History

23 Jul 2025, 20:44

Type Values Removed Values Added
First Time Aimstack aim
Aimstack
References () https://huntr.com/bounties/c85d005c-b354-4c51-a88f-adda2f09622b - () https://huntr.com/bounties/c85d005c-b354-4c51-a88f-adda2f09622b - Exploit, Third Party Advisory
CPE cpe:2.3:a:aimstack:aim:3.23.0:*:*:*:*:python:*:*
Summary
  • (es) En la versión 3.23.0 de aimhubio/aim, ciertos métodos que solicitan datos de servidores externos no tienen tiempos de espera definidos, lo que provoca que el servidor espere indefinidamente una respuesta. Esto puede provocar una denegación de servicio, ya que el servidor de seguimiento no responde a otras solicitudes mientras espera. El problema surge en el cliente que utiliza el servidor de seguimiento `aim` para comunicarse con recursos externos, concretamente en el método `_run_read_instructions` y llamadas similares sin tiempos de espera.

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-23 20:44


NVD link : CVE-2024-8061

Mitre link : CVE-2024-8061

CVE.ORG link : CVE-2024-8061


JSON object : View

Products Affected

aimstack

  • aim
CWE
CWE-400

Uncontrolled Resource Consumption