Description
Aimeos is an Open Source e-commerce framework for online shops. All SaaS and marketplace setups using Aimeos version from 2022/2023/2024 are affected by a potential denial of service attack. Users should upgrade to versions 2022.10.17, 2023.10.17, or 2024.04 of the aimeos/aimeos-core package to receive a patch.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
High
Affected products
- aimeos / aimeos-core>= 2024.04.1, < 2024.04.7 – >= 2024.04.1, < 2024.04.7
- aimeos / aimeos-core>= 2023.04.1, < 2023.10.17 – >= 2023.04.1, < 2023.10.17
- aimeos / aimeos-core>= 2022.04.1, < 2022.10.17 – >= 2022.04.1, < 2022.10.17