« Volver al listado

CVE-2025-67819

Estado: AnalizadaMedia (4.9)—

An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-67819",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-67819",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-12T19:14:28.378709Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.2
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-12T17:15:45.697",
  "references": [
    {
      "url": "https://github.com/weaviate/weaviate",
      "tags": [
        "Product"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://weaviate.io/blog/weaviate-security-release-november-2025",
      "tags": [
        "Release Notes"
      ],
      "source": "cve@mitre.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the \"Pause file activity\" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process."
    }
  ],
  "lastModified": "2026-06-17T09:58:08.260",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:weaviate:weaviate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AB306075-3057-4BB2-AE5B-2C921334F225",
              "versionEndIncluding": "1.30.19",
              "versionStartIncluding": "1.30.0"
            },
            {
              "criteria": "cpe:2.3:a:weaviate:weaviate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CC712431-DA4B-453B-8F98-5105AAB29254",
              "versionEndIncluding": "1.31.18",
              "versionStartIncluding": "1.31.0"
            },
            {
              "criteria": "cpe:2.3:a:weaviate:weaviate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "469882C7-C780-4374-8C38-60F39ADF012A",
              "versionEndIncluding": "1.32.15",
              "versionStartIncluding": "1.32.0"
            },
            {
              "criteria": "cpe:2.3:a:weaviate:weaviate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "14DB7679-8ED5-4315-8D6E-82895E5DB466",
              "versionEndIncluding": "1.33.3",
              "versionStartIncluding": "1.33.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}