CVE-2025-34438: AVideo < 20.1 IDOR Arbitrary Video Rotation
AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation metadata of any video. The endpoint verifies upload capability but fails to enforce ownership or management rights for the targeted video.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AVideoto a version that resolves this vulnerability.Fixed in 20.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34438?
The severity of CVE-2025-34438 is considered high due to its potential impact on video integrity and user trust.
How do I fix CVE-2025-34438?
To fix CVE-2025-34438, update AVideo to version 20.0 or later where the vulnerability has been addressed.
Who is affected by CVE-2025-34438?
Any users with upload permissions on AVideo versions prior to 20.0 are affected by CVE-2025-34438.
What does CVE-2025-34438 allow attackers to do?
CVE-2025-34438 allows attackers to modify video rotation metadata of any video in AVideo due to lack of ownership checks.
What are the potential consequences of CVE-2025-34438?
The potential consequences of CVE-2025-34438 include unauthorized modification of video content, leading to misrepresentation or content integrity issues.