CVE-2024-35185 describes a denial-of-service vulnerability in Minder, a software supply chain security platform, affecting versions prior to 0.0.49. An authenticated attacker can crash the Minder server by configuring a remote REST endpoint to return a large response body, leading to memory exhaustion when the Minder REST ingester attempts to process it. This vulnerability has a CVSS score of 5.3 (Medium), indicating a network-based attack with high impact on availability, but requiring low privileges and high attack complexity. Currently, there is no public exploit code available, and the vulnerability shows minimal community discussion or media coverage, suggesting it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Stacklok | Minder | < 0.0.49CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.