Aimeos denial of service vulnerability in SaaS and marketplace setups
Moderate severity
GitHub Reviewed
Published
May 29, 2024
in
aimeos/aimeos-core
•
Updated Jun 11, 2024
Package
Affected versions
>= 2024.04.1, < 2024.04.7
>= 2023.04.1, < 2023.10.17
>= 2022.04.1, < 2022.10.17
Patched versions
2024.04.7
2023.10.17
2022.10.17
Description
Published to the GitHub Advisory Database
May 29, 2024
Reviewed
May 29, 2024
Published by the National Vulnerability Database
Jun 11, 2024
Last updated
Jun 11, 2024
Impact
All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack
Patches
Upgrade to the latest 2022.10 LTS, 2023.10 LTS and 2024.04.7 version of the aimeos/aimeos-core package
References