
Cloud Vulnerability DB
A community-led vulnerabilities database
Aimeos, an Open Source e-commerce framework for online shops, disclosed a vulnerability affecting all SaaS and marketplace setups using versions from 2022/2023/2024. The vulnerability was assigned CVE-2024-37294 and was discovered on June 11, 2024. The affected component is the aimeos/aimeos-core package (GitHub Advisory, NVD).
The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium) with the vector string CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H. The vulnerability is classified as a Privilege Context Switching Error (CWE-270). The attack vector is network-based, requires low attack complexity but high privileges, and no user interaction (GitHub Advisory).
The vulnerability could lead to a potential denial of service attack against affected systems. While confidentiality impact is none, there is a low impact on integrity and high impact on availability of the system (GitHub Advisory).
The vulnerability requires high privileges to exploit but can be accessed over the network with low attack complexity. No user interaction is required for exploitation (GitHub Advisory).
Users should upgrade to versions 2022.10.17, 2023.10.17, or 2024.04 of the aimeos/aimeos-core package to receive the patch (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."