Pimcore is an Open Source Data & Experience Management Platform. The Pimcore thumbnail generation can be used to flood the server with large files. By changing the file extension or scaling factor of the requested thumbnail, attackers can create files that are much larger in file size than the original. This vulnerability is fixed in 11.2.4.
References
Configurations
History
21 Nov 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/pimcore/pimcore/commit/38af70b3130f16fc27f2aea34e2943d7bdaaba06 - Patch | |
References | () https://github.com/pimcore/pimcore/commit/a6821a16ea38086bf6012e682e1743488244bd85 - Patch | |
References | () https://github.com/pimcore/pimcore/security/advisories/GHSA-277c-5vvj-9pwx - Exploit, Vendor Advisory |
10 Jun 2024, 21:07
Type | Values Removed | Values Added |
---|---|---|
First Time |
Pimcore
Pimcore pimcore |
|
Summary |
|
|
References | () https://github.com/pimcore/pimcore/commit/38af70b3130f16fc27f2aea34e2943d7bdaaba06 - Patch | |
References | () https://github.com/pimcore/pimcore/commit/a6821a16ea38086bf6012e682e1743488244bd85 - Patch | |
References | () https://github.com/pimcore/pimcore/security/advisories/GHSA-277c-5vvj-9pwx - Exploit, Vendor Advisory | |
CPE | cpe:2.3:a:pimcore:pimcore:*:*:*:*:*:*:*:* |
04 Jun 2024, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-04 15:15
Updated : 2024-11-21 09:15
NVD link : CVE-2024-32871
Mitre link : CVE-2024-32871
CVE.ORG link : CVE-2024-32871
JSON object : View
Products Affected
pimcore
- pimcore
CWE
CWE-770
Allocation of Resources Without Limits or Throttling