CVE-2024-24752 affects Bref, a serverless PHP framework for AWS Lambda, specifically when using the Event-Driven Function runtime with a RequestHandlerInterface. The vulnerability allows an attacker to exhaust disk space on a Lambda instance by repeatedly sending multipart requests containing files, which are saved to /tmp but not deleted after processing. This denial-of-service vulnerability is rated Medium (CVSS 6.5) due to its network-based attack vector and high impact on availability, requiring low privileges and complexity. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.13CPE matchmatch criteria | cpe:2.3:a:mnapoli:bref:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.