Vulnerability Description
automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploited by sending malformed multipart requests with arbitrary characters at the end of the boundary, leading to excessive resource consumption and a complete denial of service (DoS) for all users. The vulnerability is unauthenticated, meaning no user login or interaction is required for an attacker to exploit this issue.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Automatic1111 | Stable-Diffusion-Webui | 1.10.0 |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/e6fdc6ed-f38d-4798-b60a-0e47893a81a6ExploitThird Party Advisory
FAQ
What is CVE-2024-10935?
CVE-2024-10935 is a vulnerability with a CVSS score of 7.5 (HIGH). automatic1111/stable-diffusion-webui version 1.10.0 contains a vulnerability where the server fails to handle excessive characters appended to the end of multipart boundaries. This flaw can be exploit...
How severe is CVE-2024-10935?
CVE-2024-10935 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-10935?
Check the references section above for vendor advisories and patch information. Affected products include: Automatic1111 Stable-Diffusion-Webui.