CVE-2024-11042
Last modified
CVE-2024-11042 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. EPSS estimates a 1.35% chance of exploitation in the next 30 days.
Description
In invoke-ai/invokeai version v5.0.2, the web API `POST /api/v1/images/delete` is vulnerable to Arbitrary File Deletion. This vulnerability allows unauthorized attackers to delete arbitrary files on the server, potentially including critical or sensitive system files such as SSH keys, SQLite databases, and configuration files. This can impact the integrity and availability of applications relying on these files.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-11042?
How severe is CVE-2024-11042?
How do I fix CVE-2024-11042?
Are you affected by CVE-2024-11042?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
