An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
History

Thu, 10 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Snowplow
Snowplow iglu Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:snowplow:iglu_server:*:*:*:*:*:*:*:*
Vendors & Products Snowplow
Snowplow iglu Server

Mon, 07 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Apr 2025 20:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47212, but involves a different kind of malicious payload. As above, it can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-04-03T00:00:00.000Z

Updated: 2025-04-07T18:39:59.184Z

Reserved: 2024-09-21T00:00:00.000Z

Link: CVE-2024-47214

cve-icon Vulnrichment

Updated: 2025-04-07T18:39:51.479Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-03T21:15:38.760

Modified: 2025-04-10T13:51:22.130

Link: CVE-2024-47214

cve-icon Redhat

No data.