Логотип exploitDog
bind:CVE-2024-21575
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-21575

Количество 2

Количество 2

nvd логотип

CVE-2024-21575

около 1 года назад

ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE).

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-6mx8-m8xp-f2vc

около 1 года назад

ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE).

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-21575

ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE).

CVSS3: 8.6
1%
Низкий
около 1 года назад
github логотип
GHSA-6mx8-m8xp-f2vc

ComfyUI-Impact-Pack is vulnerable to Path Traversal. The issue stems from missing validation of the `image.filename` field in a POST request sent to the `/upload/temp` endpoint added by the extension to the server. This results in writing arbitrary files to the file system which may, under some conditions, result in remote code execution (RCE).

CVSS3: 8.6
1%
Низкий
около 1 года назад

Уязвимостей на страницу