CVE-2024-12777
A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.46%
- CWE
- CWE-1088
- Published
- 2025-03-20
- Last modified
- 2026-03-13
Affected products
- aimhubio aimhubio/aim
Weakness type
Related vulnerabilities
- CVE-2026-81520 — MongoDB Connector for BI Unbounded Authentication Negotiation Leading to Connection Exhaustion
- CVE-2025-4656 — Vault Vulnerable to Recovery Key Cancellation Denial of Service
- CVE-2024-8062 — Denial of Service in h2oai/h2o-3
- CVE-2024-8061 — Denial of Service in aimhubio/aim
- CVE-2020-14483 — A timeout during a TLS handshake can result in the connection failing to terminate. This can result...