Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jhgf-xqjm-37vh

Опубликовано: 15 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's "inbox" endpoint. By abusing the "Create Activity" functionality, it is possible to create crafted playlists which will cause either denial of service or an attacker-controlled blind SSRF.

The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's "inbox" endpoint. By abusing the "Create Activity" functionality, it is possible to create crafted playlists which will cause either denial of service or an attacker-controlled blind SSRF.

EPSS

Процентиль: 13%
0.00044
Низкий

7.5 High

CVSS3

Дефекты

CWE-843

Связанные уязвимости

CVSS3: 7.5
nvd
10 месяцев назад

The vulnerability allows any attacker to cause the PeerTube server to stop functioning, or in special cases send requests to arbitrary URLs (Blind SSRF). Attackers can send ActivityPub activities to PeerTube's "inbox" endpoint. By abusing the "Create Activity" functionality, it is possible to create crafted playlists which will cause either denial of service or an attacker-controlled blind SSRF.

CVSS3: 7.5
debian
10 месяцев назад

The vulnerability allows any attacker to cause the PeerTube server to ...

EPSS

Процентиль: 13%
0.00044
Низкий

7.5 High

CVSS3

Дефекты

CWE-843