An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
History

Tue, 08 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Snowplow
Snowplow iglu Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:snowplow:iglu_server:*:*:*:*:*:*:*:*
Vendors & Products Snowplow
Snowplow iglu Server

Mon, 07 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Apr 2025 20:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Iglu Server 0.13.0 and below. It is similar to CVE-2024-47214, but involves an authenticated endpoint. It can render Iglu Server completely unresponsive. If the operation of Iglu Server is not restored, event processing in the pipeline would eventually halt.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-04-03T00:00:00.000Z

Updated: 2025-04-07T18:50:19.237Z

Reserved: 2024-09-21T00:00:00.000Z

Link: CVE-2024-47217

cve-icon Vulnrichment

Updated: 2025-04-07T18:50:11.760Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-03T21:15:38.983

Modified: 2025-04-08T18:55:43.790

Link: CVE-2024-47217

cve-icon Redhat

No data.