« Volver al listado

CVE-2025-25286

Estado: AplazadaCrítica (9.8)—

Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain configurations. The issue has been patched in `islandora/crayfish:4.1.0`. Some workarounds are available.

Leer descripción completaMostrar menos

The exploit requires making a request against the Homarus's `/convert` endpoint; therefore, the ability to exploit is much reduced if the microservice is not directly accessible from the Internet, so: Prevent general access from the Internet from hitting Homarus. Alternatively or additionally, configure auth in Crayfish to be more strongly required, such that requests with `Authorization` headers that do not validate are rejected before the problematic CLI interpolation occurs.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:N/UI:N indica explotación remota sin privilegios (T1190). FFmpeg CLI interpolation permite ejecución de comandos arbitrarios (T1059) y acceso a datos del servidor (T1005) en configuraciones expuestas de Homarus.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (2)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-25286",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-25286",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-13T15:07:56.475931Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "Islandora",
          "product": "Crayfish",
          "versions": [
            {
              "status": "affected",
              "version": "< 4.1.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-02-13T01:15:25.280",
  "references": [
    {
      "url": "https://github.com/Islandora/Crayfish/commit/64cb4cec688928798cc40e6f0a0e863d7f69fd89",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/Islandora/Crayfish/security/advisories/GHSA-mm6v-68qp-f9fw",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-150"
        },
        {
          "lang": "en",
          "value": "CWE-157"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain configurations. The issue has been patched in `islandora/crayfish:4.1.0`. Some workarounds are available. The exploit requires making a request against the Homarus's `/convert` endpoint; therefore, the ability to exploit is much reduced if the microservice is not directly accessible from the Internet, so: Prevent general access from the Internet from hitting Homarus. Alternatively or additionally, configure auth in Crayfish to be more strongly required, such that requests with `Authorization` headers that do not validate are rejected before the problematic CLI interpolation occurs."
    },
    {
      "lang": "es",
      "value": "Crayfish es una colección de microservicios de Islandora 8, uno de los cuales, Homarus, proporciona FFmpeg como microservicio. Antes de la versión 4.1.0 de Crayfish, la ejecución remota de código podía ser posible en instalaciones de Homarus accesibles desde la web en ciertas configuraciones. El problema se ha corregido en `islandora/crayfish:4.1.0`. Hay algunos workarounds disponibles. El exploit requiere realizar una solicitud contra el endpoint `/convert` de Homarus; por lo tanto, la capacidad de explotar se reduce mucho si el microservicio no es directamente accesible desde Internet, por lo tanto: Evite que el acceso general desde Internet llegue a Homarus. Como alternativa o adicionalmente, configure la autenticación en Crayfish para que sea más obligatoria, de modo que las solicitudes con encabezados `Authorization` que no validen se rechacen antes de que se produzca la interpolación de CLI problemática."
    }
  ],
  "lastModified": "2026-06-17T09:00:37.090",
  "sourceIdentifier": "security-advisories@github.com"
}