The zanllp sd-webui-infinite-image-browsing (aka Infinite Image Browsing) extension before 977815a for stable-diffusion-webui (aka Stable Diffusion web UI), if Gradio authentication is enabled without secret key configuration, allows remote attackers to read any local file via /file?path= in the URL, as demonstrated by reading /proc/self/environ to discover credentials.
References
Link | Resource |
---|---|
https://github.com/zanllp/sd-webui-infinite-image-browsing/issues/387 | Issue Tracking Vendor Advisory |
https://github.com/zanllp/sd-webui-infinite-image-browsing/pull/368/commits/977815a2b28ad953c10ef0114c365f698c4b8f19 | Patch |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2023-10-22T00:00:00
Updated: 2023-10-22T21:44:50.784091
Reserved: 2023-10-22T00:00:00
Link: CVE-2023-46315
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-10-22T22:15:08.797
Modified: 2023-10-30T19:09:47.337
Link: CVE-2023-46315
JSON object: View
Redhat Information
No data.
CWE