Логотип exploitDog
bind:CVE-2024-11042
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-11042

Количество 2

Количество 2

nvd логотип

CVE-2024-11042

4 месяца назад

In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-227r-w5j2-6243

4 месяца назад

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-11042

In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.

CVSS3: 9.1
1%
Низкий
4 месяца назад
github логотип
GHSA-227r-w5j2-6243

InvokeAI Arbitrary File Deletion vulnerability

CVSS3: 9.1
1%
Низкий
4 месяца назад

Уязвимостей на страницу