CVE-2024-12777 Information
Mar 21, 2025
cve
Description
A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server which is single-threaded can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time preventing it from responding to other requests.
Reference
https://huntr.com/bounties/cdf8db79-c290-4fe5-9383-4c518bfba4a8 https://huntr.com/bounties/cdf8db79-c290-4fe5-9383-4c518bfba4a8
Share on: