CyberRota Analysis
AI-GeneratedThe vulnerability affects Cloudreve, a self-hosted file management system, where an authenticated user with Files.Write permission can exploit a flaw in the PrepareUpload function to bypass storage quotas. This allows users to reserve more storage than permitted, potentially exhausting host storage and denying upload capabilities to other users. Organizations using versions prior to 4.18.0 should prioritize updating to mitigate the risk of storage exhaustion and service disruption.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditional storage charge outside the same quota-enforcing transaction. An authenticated user with Files.Write permission can issue concurrent upload-session requests that read the same capacity snapshot, all pass the MaxStorage check, and reserve their declared sizes through CommitWithStorageDiff. The resulting reservations can exceed the account quota and can be materialized as chunked uploads that exhaust host storage and deny uploads to other users. The default local-storage policy and default User group are affected. This issue is fixed in version 4.18.0.