An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throughput).
History

Wed, 23 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Snowplow
Snowplow snowbridge
CPEs cpe:2.3:a:snowplow:snowbridge:-:*:*:*:*:*:*:*
Vendors & Products Snowplow
Snowplow snowbridge

Mon, 07 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-703
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Apr 2025 20:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Snowbridge setups sending data to Google Tag Manager Server Side. It involves attaching an invalid GTM SS preview header to events, causing them to be retried indefinitely. As a result, the performance of forwarding events to GTM SS overall can be affected (latency, throughput).
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-04-03T00:00:00.000Z

Updated: 2025-04-07T18:43:56.871Z

Reserved: 2024-09-21T00:00:00.000Z

Link: CVE-2024-47215

cve-icon Vulnrichment

Updated: 2025-04-07T18:43:30.413Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-03T21:15:38.873

Modified: 2025-04-23T14:55:42.590

Link: CVE-2024-47215

cve-icon Redhat

No data.