7.5
CVE-2024-48080
- EPSS 0.67%
- Veröffentlicht 03.12.2024 19:15:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue in aedes v0.51.2 allows attackers to cause a Denial of Service(DoS) via a crafted request. NOTE: the Supplier indicates that exploitation cannot occur because of the protection mechanism in the validateTopic function in lib/utils.js.
Daten sind bereitgestellt durch das CVE Programm von Authorized Data Publishers (ADP) (Unstrukturiert)
Herstelleraedes_project
≫
Produkt
aedes
Default Statusunknown
Version
0.51.2
Version <
0.51.3
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.67% | 0.473 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-770 Allocation of Resources Without Limits or Throttling
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
https://gist.github.com/mcollina/f06af2098665e4bb8372104425f3999e
https://gist.github.com/pengwGit/cd3c1701a9e05b424fa6c60d86845de4
https://github.com/moscajs/aedes/issues/1024
https://github.com/moscajs/aedes/issues/1024#issuecomment-2671695219
https://github.com/moscajs/aedes/releases/tag/v0.51.2