PT-2025-50958 · Weaviate · Weaviate Oss
CVE-2025-67819
·
Publicado
2025-12-12
·
Atualizado
2026-07-30
CVSS v4.0
8.7
Alta
| Vetor | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Weaviate OSS versions prior to 1.33.4
Description
A flaw exists in Weaviate OSS that allows an attacker to read arbitrary files accessible to the service process. This occurs because of insufficient validation of the
fileName field during file transfer operations. Specifically, an attacker who can call the GetFile method while a shard is paused and the FileReplicationService is reachable can exploit this issue.Recommendations
Update Weaviate OSS to version 1.33.4 or later.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Weaviate Oss