PT-2025-12095 · Invokeai · Invokeai
Publicado
2025-03-20
·
Atualizado
2025-03-20
·
CVE-2024-11043
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
invoke-ai/invokeai version v5.0.2
Description
A Denial of Service (DoS) issue was discovered in the "/api/v1/boards/{board id}" endpoint. This occurs when an excessively large payload is sent in the
board name field during a PATCH request, causing the UI to become unresponsive and making it impossible for users to interact with or manage the affected board. The option to delete the board also becomes inaccessible.Recommendations
For invoke-ai/invokeai version v5.0.2, consider restricting access to the "/api/v1/boards/{board id}" endpoint to prevent exploitation until a fix is available. As a temporary workaround, limit the size of the payload that can be sent in the
board name field to prevent the UI from becoming unresponsive.Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Invokeai