Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-50235 | A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations. |
| Link | Providers |
|---|---|
| https://github.com/CERTCC/VINCE/issues?q=label%3Asecurity |
|
Thu, 17 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cert
Cert vince |
|
| CPEs | cpe:2.3:a:cert:vince:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cert
Cert vince |
|
| Metrics |
cvssV3_1
|
Tue, 15 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Potential DOS Vulnerability exists in CERT VINCE software prior to version 3.0.8. An authenticated administrative user can inject an arbitrary pickle object as part of a user's profile. This can lead to a potential DoS on the server when the user's profile is accessed. Django server does restrict unpickling from crashing the server. | A potential denial-of-service (DoS) vulnerability exists in CERT VINCE software versions prior to 3.0.8. An authenticated administrative user can inject an arbitrary pickle object into a user’s profile, which may lead to a DoS condition when the profile is accessed. While the Django server restricts unpickling to prevent server crashes, this vulnerability could still disrupt operations. |
| Title | A Potential DOS Vulnerability exists in CERT software prior to version 3.0.8 | Potential DoS Vulnerability in CERT VINCE Software Before Version 3.0.8 |
Mon, 14 Oct 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Potential DOS Vulnerability exists in CERT VINCE software prior to version 3.0.8. An authenticated administrative user can inject an arbitrary pickle object as part of a user's profile. This can lead to a potential DoS on the server when the user's profile is accessed. Django server does restrict unpickling from crashing the server. | |
| Title | A Potential DOS Vulnerability exists in CERT software prior to version 3.0.8 | |
| Weaknesses | CWE-502 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-03-20T18:58:47.620Z
Reserved: 2024-10-14T20:49:18.194Z
Link: CVE-2024-9953
Updated: 2024-10-15T15:41:19.123Z
Status : Modified
Published: 2024-10-14T22:15:03.957
Modified: 2025-03-20T19:15:36.063
Link: CVE-2024-9953
No data.
OpenCVE Enrichment
No data.
EUVD