← العودة للجدول
CVE-2025-25286
CVE-2025-25286 — Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, pr
📅 2025-02-13
🔴 Critical 🔥 No NVD Exploit OT/ICS CVSS 9.8 🎯 EPSS 4.38%

📋 الوصف الكامل

Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior to Crayfish version 4.1.0, remote code execution may be possible in web-accessible installations of Homarus in certain configurations. The issue has been patched in `islandora/crayfish:4.1.0`. Some workarounds are available. The exploit requires making a request against the Homaru

💻 الأنظمة المتأثرة

Crayfish is a

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2025-25286

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v4.1.0

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←