Impact
FileBrowser versions prior to 2.63.19 do not enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint. As a result, authenticated users can submit request bodies that exceed the specified length and cause the application to write arbitrary, oversized data to disk. This excessive disk usage leads to exhaustion of storage resources and ultimately makes the service unavailable.
Affected Systems
The vulnerability affects the FileBrowser application for all releases before version 2.63.19 released by the filebrowser vendor. Any installation of these earlier editions connected to an authenticated data store is susceptible.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high. EPSS data is not provided, and the issue is not listed in the CISA KEV catalog. The attack requires legitimate user credentials, implying an insider, compromised account, or a system with weak access controls. Once exploited, the attacker can consume disk space to render FileBrowser non-functional, causing denial of service and potential data loss.
OpenCVE Enrichment