Added |
Description |
|
Record truncated, showing 500 of 682 characters.
View Entire Change Record
stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input into the config_save_name variable on line 653. This user input is later used in the save_config_state method and used to create a file path on line 65, which is afterwards opened for writing on line 67, which leads to a
|
Added |
CVSS V3.1 |
|
GitHub, Inc. AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
|
Added |
CWE |
|
GitHub, Inc. CWE-22
|
Added |
Reference |
|
GitHub, Inc. https://github.com/AUTOMATIC1111/stable-diffusion-webui/blob/cf2772fab0af5573da775e7437e6acdca424f26e/modules/ui_extensions.py#L59 [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://github.com/AUTOMATIC1111/stable-diffusion-webui/blob/cf2772fab0af5573da775e7437e6acdca424f26e/modules/ui_extensions.py#L646-L660 [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://github.com/AUTOMATIC1111/stable-diffusion-webui/blob/cf2772fab0af5573da775e7437e6acdca424f26e/modules/ui_extensions.py#L65 [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://github.com/AUTOMATIC1111/stable-diffusion-webui/blob/cf2772fab0af5573da775e7437e6acdca424f26e/modules/ui_extensions.py#L653 [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://github.com/AUTOMATIC1111/stable-diffusion-webui/blob/cf2772fab0af5573da775e7437e6acdca424f26e/modules/ui_extensions.py#L67 [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://github.com/AUTOMATIC1111/stable-diffusion-webui/blob/v1.7.0/modules/ui_extensions.py [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://github.com/AUTOMATIC1111/stable-diffusion-webui/commit/d9708c92b444894bce8070e4dcfaa093f8eb8d43 [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://github.com/AUTOMATIC1111/stable-diffusion-webui/discussions/15461 [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://securitylab.github.com/advisories/GHSL-2024-010_stable-diffusion-webui [No types assigned]
|
Added |
Reference |
|
GitHub, Inc. https://securitylab.github.com/advisories/GHSL-2024-010_stable-diffusion-webui/ [No types assigned]
|