CVE-2024-8061 Information
Mar 21, 2025
cve
Description
In version 3.23.0 of aimhubio/aim certain methods that request data from external servers do not have set timeouts causing the server to wait indefinitely for a response. This can lead to a denial of service as the tracking server does not respond to other requests while waiting. The issue arises in the client used by the aim tracking server to communicate with external resources specifically in the _run_read_instructions method and similar calls without timeouts.
Reference
https://huntr.com/bounties/c85d005c-b354-4c51-a88f-adda2f09622b
Share on: