← voltar
CVE-2025-32944

PeerTube User Import Authenticated Persistent Denial of Service

CVSS 6.5 MEDIUMEPSS 0.5%CWE-248
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.5EPSS 0.5%KEV nãoPoC Patch referenciado
Ciclo de vida
15 abr 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner.  If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. If the yauzl library encounters a filename that is considered illegal, it raises an exception that is uncaught by PeerTube, leading to a crash which repeats infinitely on startup.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Produtos afetados
Chocobozzz/PeerTube

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →