CVE-2024-8061
- EPSS 0.11%
- Veröffentlicht 20.03.2025 10:10:09
- Zuletzt bearbeitet 15.10.2025 13:15:54
In version 3.23.0 of aimhubio/aim, certain methods that request data from external servers do not have set timeouts, causing the server to wait indefinitely for a response. This can lead to a denial of service, as the tracking server does not respond...
CVE-2024-6851
- EPSS 0.29%
- Veröffentlicht 20.03.2025 10:09:55
- Zuletzt bearbeitet 23.07.2025 20:57:20
In version 3.22.0 of aimhubio/aim, the LocalFileManager._cleanup function in the aim tracking server accepts a user-specified glob-pattern for deleting files. The function does not verify that the matched files are within the directory managed by Loc...
CVE-2024-6483
- EPSS 0.29%
- Veröffentlicht 20.03.2025 10:09:36
- Zuletzt bearbeitet 23.07.2025 20:57:02
A vulnerability in the `runs/delete-batch` endpoint of aimhubio/aim version 3.19.3 allows for arbitrary file or directory deletion through path traversal. The endpoint does not mitigate path traversal when handling user-specified run-names, which are...
CVE-2024-10110
- EPSS 0.15%
- Veröffentlicht 20.03.2025 10:09:22
- Zuletzt bearbeitet 23.07.2025 20:56:54
In version 3.23.0 of aimhubio/aim, the ScheduledStatusReporter object can be instantiated to run on the main thread of the tracking server, leading to the main thread being blocked indefinitely. This results in a denial of service as the tracking ser...
CVE-2024-7760
- EPSS 0.07%
- Veröffentlicht 20.03.2025 10:09:04
- Zuletzt bearbeitet 21.07.2025 19:47:31
aimhubio/aim version 3.22.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the tracking server. The vulnerability is due to overly permissive CORS settings, allowing cross-origin requests from all origins. This enables CSRF attacks on ...
CVE-2025-0190
- EPSS 0.14%
- Veröffentlicht 20.03.2025 10:08:48
- Zuletzt bearbeitet 28.03.2025 14:28:25
In version 3.25.0 of aimhubio/aim, a denial of service vulnerability exists. By tracking a large number of `Text` objects and then querying them simultaneously through the web API, the Aim web server becomes unresponsive to other requests for an exte...
CVE-2024-8863
- EPSS 0.18%
- Veröffentlicht 14.09.2024 23:15:11
- Zuletzt bearbeitet 20.09.2024 15:43:43
A vulnerability, which was classified as problematic, was found in aimhubio aim up to 3.24. Affected is the function dangerouslySetInnerHTML of the file textbox.tsx of the component Text Explorer. The manipulation of the argument query leads to cross...
CVE-2024-6578
- EPSS 0.22%
- Veröffentlicht 29.07.2024 19:15:13
- Zuletzt bearbeitet 21.11.2024 09:49:55
A stored cross-site scripting (XSS) vulnerability exists in aimhubio/aim version 3.19.3. The vulnerability arises from the improper neutralization of input during web page generation, specifically in the logs-tab for runs. The terminal output logs ar...
CVE-2024-6396
- EPSS 90.83%
- Veröffentlicht 12.07.2024 00:15:01
- Zuletzt bearbeitet 23.07.2025 20:56:39
A vulnerability in the `_backup_run` function in aimhubio/aim version 3.19.3 allows remote attackers to overwrite any file on the host server and exfiltrate arbitrary data. The vulnerability arises due to improper handling of the `run_hash` and `repo...
CVE-2024-6227
- EPSS 0.27%
- Veröffentlicht 08.07.2024 19:15:10
- Zuletzt bearbeitet 21.11.2024 09:49:14
A vulnerability in aimhubio/aim version 3.19.3 allows an attacker to cause an infinite loop by configuring the remote tracking server to point at itself. This results in the server endlessly connecting to itself, rendering it unable to respond to oth...