CVE-2025-67819
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-22
Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
12/12/2025
Última modificación:
12/12/2025
Descripción
*** Pendiente de traducción *** An issue was discovered in Weaviate OSS before 1.33.4. Due to a lack of validation of the fileName field in the transfer logic, an attacker who can call the GetFile method while a shard is in the "Pause file activity" state and the FileReplicationService is reachable can read arbitrary files accessible to the service process.
Impacto
Puntuación base 3.x
4.90
Gravedad 3.x
MEDIA



