CVE Vulnerabilities

CVE-2024-12777

Synchronous Access of Remote Resource without Timeout

Published: Mar 20, 2025 | Modified: Jul 18, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in aimhubio/aim version 3.25.0 allows for a denial of service through the misuse of the sshfs-client. The tracking server, which is single-threaded, can be made unresponsive by requesting it to connect to an unresponsive socket via sshfs. The lack of an additional timeout setting in the sshfs-client causes the server to hang for a significant amount of time, preventing it from responding to other requests.

Weakness

The code has a synchronous call to a remote resource, but there is no timeout for the call, or the timeout is set to infinite.

Affected Software

NameVendorStart VersionEnd Version
AimAimstack3.25.0 (including)3.25.0 (including)

References