Snowplow Enrich
cpe:2.3:a:snowplow:enrich:*:*:*:*:*:*:*
- <= 5.1.0
A denial-of-service vulnerability has been identified in Snowplow Enrich versions through 5.1.0. The issue arises when a maliciously crafted Snowplow event is sent to the pipeline. The Enrich process crashes while validating the event and then attempts to restart indefinitely, disrupting event processing.
Exploitation of this vulnerability causes the Enrich process to crash and restart repeatedly, halting event processing in the pipeline.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.