Vulnerability Description
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `find_and_replace` function. This vulnerability is fixed in 23.1.5.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bmaltais | Kohya Ss | >= 22.6.1, < 24.0.1 |
Related Weaknesses (CWE)
References
- https://github.com/bmaltais/kohya_ss/commit/8bc67a7467f8366db1a4b9b3b14525ec763fPatch
- https://github.com/bmaltais/kohya_ss/security/advisories/GHSA-p945-7qm7-7j53Third Party Advisory
- https://securitylab.github.com/advisories/GHSL-2024-019_GHSL-2024-024_kohya_ssExploitThird Party Advisory
- https://github.com/bmaltais/kohya_ss/commit/8bc67a7467f8366db1a4b9b3b14525ec763fPatch
- https://github.com/bmaltais/kohya_ss/security/advisories/GHSA-p945-7qm7-7j53Third Party Advisory
- https://securitylab.github.com/advisories/GHSL-2024-019_GHSL-2024-024_kohya_ssExploitThird Party Advisory
FAQ
What is CVE-2024-32023?
CVE-2024-32023 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a path injection in the `common_gui.py` `find_and_replace` function. This vulnerability is fixed in 23.1.5.
How severe is CVE-2024-32023?
CVE-2024-32023 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-32023?
Check the references section above for vendor advisories and patch information. Affected products include: Bmaltais Kohya Ss.