CVE-2024-12882: SSRF in comfyanonymous/comfyui
comfyanonymous/comfyui version v0.2.4 suffers from a non-blind Server-Side Request Forgery (SSRF) vulnerability. This vulnerability can be exploited by combining the REST APIs POST /internal/models/download and GET /view, allowing attackers to abuse the victim server's credentials to access unauthorized web resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12882?
The severity of CVE-2024-12882 is classified as high due to its potential for exploitation through Server-Side Request Forgery.
How do I fix CVE-2024-12882?
To fix CVE-2024-12882, update to the latest version of comfyui that addresses this vulnerability.
What is the impact of CVE-2024-12882?
CVE-2024-12882 allows attackers to exploit the server's internal requests, possibly accessing sensitive information through unauthorized means.
Which software is affected by CVE-2024-12882?
The affected software by CVE-2024-12882 is comfyui version v0.2.4.
Can CVE-2024-12882 be exploited remotely?
Yes, CVE-2024-12882 can be exploited remotely by sending crafted requests to the affected server's APIs.