This vulnerability affects Snowplow Collector 3.x before 3.3.0 (unless it’s set up behind a reverse proxy that establishes payload limits). It involves sending very large payloads to the Collector and can render it unresponsive to the rest of the requests. As a result, data would not enter the pipeline and would be potentially lost.
References
Configurations
History
No history.
Information
Published : 2025-04-03 21:15
Updated : 2025-04-15 19:29
NVD link : CVE-2024-56528
Mitre link : CVE-2024-56528
CVE.ORG link : CVE-2024-56528
JSON object : View
Products Affected
snowplow
- stream_collector
CWE
CWE-400
Uncontrolled Resource Consumption
