// For flags

CVE-2024-32871

Pimcore Vulnerable to Flooding Server with Thumbnail files

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Attend
*SSVC
Descriptions

Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in file size than the original. This vulnerability is fixed in 11.2.4.

Pimcore es una plataforma de gestión de experiencias y datos de código abierto. La generación de miniaturas de Pimcore se puede utilizar para inundar el servidor con archivos grandes. Al cambiar la extensión del archivo o el factor de escala de la miniatura solicitada, los atacantes pueden crear archivos cuyo tamaño sea mucho mayor que el original. Esta vulnerabilidad se solucionó en 11.2.4.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:Attend
Exploitation
None
Automatable
Yes
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-04-19 CVE Reserved
  • 2024-06-04 CVE Published
  • 2024-06-11 EPSS Updated
  • 2024-08-02 CVE Updated
  • 2024-08-02 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Pimcore
Search vendor "Pimcore"
Pimcore
Search vendor "Pimcore" for product "Pimcore"
>= 11.0.0 < 11.2.4
Search vendor "Pimcore" for product "Pimcore" and version " >= 11.0.0 < 11.2.4"
-
Affected