PT-2025-14801 · Enrich · Enrich

Published

2025-04-03

·

Updated

2025-04-04

·

CVE-2024-47213

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Enrich versions 5.1.0 and below
Description The issue involves sending a maliciously crafted Snowplow event to the pipeline, causing Enrich to crash and attempt to restart indefinitely, resulting in halted event processing.
Recommendations For Enrich versions 5.1.0 and below, as a temporary workaround, consider restricting the reception of Snowplow events to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-47213

Affected Products

Enrich