漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PeerTube User Import Authenticated Persistent Denial of Service
Vulnerability Description
The vulnerability allows any authenticated user to cause the PeerTube server to stop functioning in a persistent manner. If user import is enabled (which is the default setting), any registered user can upload an archive for importing. The code uses the yauzl library for reading the archive. If the yauzl library encounters a filename that is considered illegal, it raises an exception that is uncaught by PeerTube, leading to a crash which repeats infinitely on startup.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未捕获的异常
Vulnerability Title
PeerTube 安全漏洞
Vulnerability Description
PeerTube是Chocobozzz开源的一个去中心化的视频分享服务平台。用于制作视频项目。 PeerTube存在安全漏洞,该漏洞源于未捕获异常,可能导致服务器崩溃。
CVSS Information
N/A
Vulnerability Type
N/A