CVE Vulnerabilities

CVE-2024-47173

Privilege Context Switching Error

Published: Oct 24, 2024 | Modified: Oct 24, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Aimeos is an e-commerce framework. All SaaS and marketplace setups using the Aimeos GraphQL API admin interface version from 2024.04 up to 2024.07.1 are affected by a potential denial of service attack. Version 2024.07.2 fixes the issue.

Weakness

The product does not properly manage privileges while it is switching between different contexts that have different privileges or spheres of control.

Potential Mitigations

References