PT-2024-24930 · Frigate · Frigate

Sim4N6

·

Published

2024-05-09

·

Updated

2024-05-14

·

CVE-2024-32874

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Frigate versions prior to 0.13.2
Description The issue arises from the lack of limitation on the length of filenames and the costly use of Unicode normalization with the form NFKD under the hood of the secure filename() function. This can lead to an application-level denial of service when a user intentionally uploads a file or retrieves a filename with a large Unicode name.
Recommendations For versions prior to 0.13.2, update to version 0.13.2 or later to resolve the issue. As a temporary workaround, consider restricting the length of filenames to prevent intentional denial of service attacks.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2024-32874
GHSA-W4H6-9WRP-V5JQ

Affected Products

Frigate