PT-2025-12215 · Aimhubio · Aim

Published

2025-03-20

·

Updated

2025-07-23

·

CVE-2024-8061

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions aimhubio/aim version 3.23.0
Description The application contains methods that request data from external servers without defined timeouts. This can cause the server to wait indefinitely for a response, potentially leading to a denial of service, as the tracking server becomes unresponsive to other requests while awaiting a response. The issue is present in the client used by the aim tracking server to communicate with external resources, specifically within the run read instructions method and similar calls lacking timeouts.
Recommendations aimhubio/aim version 3.23.0: Implement timeouts for all methods that request data from external servers to prevent indefinite waiting and potential denial of service. Specifically, address the run read instructions method and similar calls to ensure they include appropriate timeout mechanisms.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2024-8061
GHSA-6W7P-XRVP-P7XV

Affected Products

Aim