« Volver al listado

CVE-2025-32949

Estado: AnalizadaMedia (6.5)—

This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when extracting a Zip Bomb.

If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. The yauzl library does not contain any mechanism to detect or prevent extraction of a Zip Bomb https://en.wikipedia.org/wiki/Zip_bomb . Therefore, when using the User Import functionality with a Zip Bomb, PeerTube will try extracting the archive which will cause a disk space resource exhaustion.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-32949",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-32949",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-15T15:17:54.706744Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "reefs@jfrog.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "reefs@jfrog.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "7.1.1",
              "versionType": "custom"
            }
          ],
          "packageName": "Chocobozzz/PeerTube",
          "collectionURL": "https://github.com",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-04-15T15:16:09.607",
  "references": [
    {
      "url": "https://github.com/Chocobozzz/PeerTube/releases/tag/v7.1.1",
      "tags": [
        "Release Notes"
      ],
      "source": "reefs@jfrog.com"
    },
    {
      "url": "https://research.jfrog.com/vulnerabilities/peertube-archive-resource-exhaustion/",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "reefs@jfrog.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "reefs@jfrog.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-409"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "This vulnerability allows any authenticated user to cause the server to consume very large amounts of disk space when extracting a Zip Bomb. \n\nIf user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. The yauzl library does not contain any mechanism to detect or prevent extraction of a  Zip Bomb https://en.wikipedia.org/wiki/Zip_bomb . Therefore, when using the User Import functionality with a Zip Bomb, PeerTube will try extracting the archive which will cause a disk space resource exhaustion."
    },
    {
      "lang": "es",
      "value": "Esta vulnerabilidad permite que cualquier usuario autenticado haga que el servidor consuma grandes cantidades de espacio en disco al extraer Zip Bomb. Si la importación de usuarios está habilitada (configuración predeterminada), cualquier usuario registrado puede cargar un archivo para su importación. El código utiliza la librería yauzl para leer el archivo. Esta librería no contiene ningún mecanismo para detectar o prevenir la extracción de Zip Bomb (https://en.wikipedia.org/wiki/Zip_bomb). Por lo tanto, al usar la función de importación de usuarios con Zip Bomb, PeerTube intentará extraer el archivo, lo que agotará el espacio en disco."
    }
  ],
  "lastModified": "2026-06-17T09:12:51.010",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:framasoft:peertube:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8E26564-C5EB-4B35-9E6B-2B4C4297D307",
              "versionEndExcluding": "7.1.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "reefs@jfrog.com"
}