aimhubio aim Denial-of-Service Vulnerability Due to Missing Timeouts in External Data Requests
Vulnerability
A denial-of-service vulnerability has been identified in aimhubio aim version 3.23.0. Certain methods in the client used by the aim tracking server to request data from external servers do not have timeouts set. This oversight causes the server to wait indefinitely for a response, leading to a denial-of-service condition where the tracking server cannot respond to other requests while waiting. The issue arises in the '_run_read_instructions' method and similar calls that lack timeouts, causing the tracking server to become unresponsive.
Impact
Exploitation of this vulnerability causes a complete denial-of-service condition on the aim tracking server, preventing it from responding to any other requests.
Reproduction
The vulnerability can be reproduced by starting an aim tracking server and a second instance to complete the initial handshake. After the handshake, the second instance can be swapped for a Flask server that hangs on specific requests. Once this is set up, the aim tracking server will be unable to respond to other requests, demonstrating the denial-of-service condition.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
