Remote File Exposure in Infinite Image Browsing Extension for Stable Diffusion Web UI
CVE-2023-46315

7.5HIGH

Key Information:

Vendor

Zanllp

Vendor
CVE Published:
22 October 2023

What is CVE-2023-46315?

The Infinite Image Browsing extension for Stable Diffusion web UI has a vulnerability when Gradio authentication is activated without configuring a secret key. This flaw allows remote attackers to exploit the system to read local files by appending specific paths in the URL. This can disclose sensitive information, including environment variables and credentials, posing significant security risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.