Assigner | GitHub_M |
Reserved | 2024-06-05 |
Published | 2024-06-11 |
Updated | 2024-06-11 |
Description
Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users should upgrade to versions 2022.10.17, 2023.10.17, or 2024.04 of the aimeos/aimeos-core package to receive a patch.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H |
Problem types
CWE-270: Privilege Context Switching Error
Product status
>= 2023.04.1, < 2023.10.17
>= 2022.04.1, < 2022.10.17
References
https://github.com/aimeos/aimeos-core/security/advisories/GHSA-xjm6-jfmg-qc6p