CVE-2024-9953
Potential DoS Vulnerability in CERT VINCE Software Before Version 3.0.8
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A Potential DOS Vulnerability exists in CERT VINCE software prior to version 3.0.8. An authenticated administrative user can inject an arbitrary pickle object as part of a user's profile. This can lead to a potential DoS on the server when the user's profile is accessed. Django server does restrict unpickling from crashing the server.
A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-10-14 CVE Reserved
- 2024-10-14 CVE Published
- 2024-10-15 CVE Updated
- 2024-10-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/CERTCC/VINCE/issues?q=label%3Asecurity |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
CERT/CC Search vendor "CERT/CC" | VINCE - Vulnerability Information And Coordination Environment Search vendor "CERT/CC" for product "VINCE - Vulnerability Information And Coordination Environment" | < 3.0.8 Search vendor "CERT/CC" for product "VINCE - Vulnerability Information And Coordination Environment" and version " < 3.0.8" | en |
Affected
|