An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
History

Tue, 08 Apr 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Snowplow
Snowplow iglu Server
CPEs cpe:2.3:a:snowplow:iglu_server:*:*:*:*:*:*:*:*
Vendors & Products Snowplow
Snowplow iglu Server

Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Apr 2025 20:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Iglu Server 0.13.0 and below. It involves sending very large payloads to a particular API endpoint of Iglu Server and can render it completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-04-03T00:00:00.000Z

Updated: 2025-04-04T15:15:29.113Z

Reserved: 2024-09-21T00:00:00.000Z

Link: CVE-2024-47212

cve-icon Vulnrichment

Updated: 2025-04-04T15:15:03.685Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-03T21:15:38.523

Modified: 2025-04-08T20:06:27.003

Link: CVE-2024-47212

cve-icon Redhat

No data.