Skip to content

Commit ba14a70

Browse files
tooryxcopybara-github
authored andcommitted
Add an identifier for the advisory generated by Doyensec's ComfyUI detectors.
PiperOrigin-RevId: 748312760 Change-Id: I8bf1f99e7de57c97e4725143b0b0ca0b88ea984f
1 parent cb84cf1 commit ba14a70

File tree

8 files changed

+24
-8
lines changed

8 files changed

+24
-8
lines changed

doyensec/detectors/comfyui_arbitrary_read_filename/src/main/java/com/google/tsunami/plugins/detectors/comfyui/filenameread/ComfyUiFileReadViaFilename.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -375,7 +375,9 @@ private DetectionReport buildDetectionReport(
375375
.setVulnerability(
376376
Vulnerability.newBuilder()
377377
.setMainId(
378-
VulnerabilityId.newBuilder().setPublisher(VULNERABILITY_REPORT_PUBLISHER))
378+
VulnerabilityId.newBuilder()
379+
.setPublisher(VULNERABILITY_REPORT_PUBLISHER)
380+
.setValue("COMFYUI_2025_FILE_READ_FILENAME"))
379381
.setSeverity(Severity.CRITICAL)
380382
.setTitle(VULNERABILITY_REPORT_TITLE)
381383
.setDescription(VULNERABILITY_REPORT_DESCRIPTION)

doyensec/detectors/comfyui_arbitrary_read_filename/src/test/java/com/google/tsunami/plugins/detectors/comfyui/filenameread/ComfyUiFileReadViaFilenameTest.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -156,7 +156,9 @@ private DetectionReport generateDetectionReport(
156156
.setVulnerability(
157157
Vulnerability.newBuilder()
158158
.setMainId(
159-
VulnerabilityId.newBuilder().setPublisher(VULNERABILITY_REPORT_PUBLISHER))
159+
VulnerabilityId.newBuilder()
160+
.setPublisher(VULNERABILITY_REPORT_PUBLISHER)
161+
.setValue("COMFYUI_2025_FILE_READ_FILENAME"))
160162
.setSeverity(Severity.CRITICAL)
161163
.setTitle(VULNERABILITY_REPORT_TITLE)
162164
.setDescription(VULNERABILITY_REPORT_DESCRIPTION)

doyensec/detectors/comfyui_arbitrary_read_savepath/src/main/java/com/google/tsunami/plugins/detectors/comfyui/savepathread/ComfyUiFileReadViaSavePath.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -380,7 +380,9 @@ private DetectionReport buildDetectionReport(
380380
.setVulnerability(
381381
Vulnerability.newBuilder()
382382
.setMainId(
383-
VulnerabilityId.newBuilder().setPublisher(VULNERABILITY_REPORT_PUBLISHER))
383+
VulnerabilityId.newBuilder()
384+
.setPublisher(VULNERABILITY_REPORT_PUBLISHER)
385+
.setValue("COMFYUI_2025_FILE_READ_SAVEPATH"))
384386
.setSeverity(Severity.CRITICAL)
385387
.setTitle(VULNERABILITY_REPORT_TITLE)
386388
.setDescription(VULNERABILITY_REPORT_DESCRIPTION)

doyensec/detectors/comfyui_arbitrary_read_savepath/src/test/java/com/google/tsunami/plugins/detectors/comfyui/savepathread/ComfyUiFileReadViaSavePathTest.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -156,7 +156,9 @@ private DetectionReport generateDetectionReport(
156156
.setVulnerability(
157157
Vulnerability.newBuilder()
158158
.setMainId(
159-
VulnerabilityId.newBuilder().setPublisher(VULNERABILITY_REPORT_PUBLISHER))
159+
VulnerabilityId.newBuilder()
160+
.setPublisher(VULNERABILITY_REPORT_PUBLISHER)
161+
.setValue("COMFYUI_2025_FILE_READ_SAVEPATH"))
160162
.setSeverity(Severity.CRITICAL)
161163
.setTitle(VULNERABILITY_REPORT_TITLE)
162164
.setDescription(VULNERABILITY_REPORT_DESCRIPTION)

doyensec/detectors/comfyui_exposed_ui_detector/src/main/java/com/google/tsunami/plugins/detectors/comfyui/exposed/ComfyUiExposedUi.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -190,7 +190,9 @@ private DetectionReport buildDetectionReport(
190190
.setVulnerability(
191191
Vulnerability.newBuilder()
192192
.setMainId(
193-
VulnerabilityId.newBuilder().setPublisher(VULNERABILITY_REPORT_PUBLISHER))
193+
VulnerabilityId.newBuilder()
194+
.setPublisher(VULNERABILITY_REPORT_PUBLISHER)
195+
.setValue("COMFYUI_EXPOSED_UI"))
194196
.setSeverity(Severity.CRITICAL)
195197
.setTitle(VULNERABILITY_REPORT_TITLE)
196198
.setDescription(VULNERABILITY_REPORT_DESCRIPTION)

doyensec/detectors/comfyui_exposed_ui_detector/src/test/java/com/google/tsunami/plugins/detectors/comfyui/exposed/ComfyUiExposedUiTest.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -145,7 +145,9 @@ private DetectionReport generateDetectionReport(
145145
.setVulnerability(
146146
Vulnerability.newBuilder()
147147
.setMainId(
148-
VulnerabilityId.newBuilder().setPublisher(VULNERABILITY_REPORT_PUBLISHER))
148+
VulnerabilityId.newBuilder()
149+
.setPublisher(VULNERABILITY_REPORT_PUBLISHER)
150+
.setValue("COMFYUI_EXPOSED_UI"))
149151
.setSeverity(Severity.CRITICAL)
150152
.setTitle(VULNERABILITY_REPORT_TITLE)
151153
.setDescription(VULNERABILITY_REPORT_DESCRIPTION)

doyensec/detectors/comfyui_preauth_rce/src/main/java/com/google/tsunami/plugins/detectors/comfyui/rce/ComfyUiRemoteCodeExecution.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -276,7 +276,9 @@ private DetectionReport buildDetectionReport(
276276
.setVulnerability(
277277
Vulnerability.newBuilder()
278278
.setMainId(
279-
VulnerabilityId.newBuilder().setPublisher(VULNERABILITY_REPORT_PUBLISHER))
279+
VulnerabilityId.newBuilder()
280+
.setPublisher(VULNERABILITY_REPORT_PUBLISHER)
281+
.setValue("COMFYUI_2025_PREAUTH_RCE"))
280282
.setSeverity(Severity.CRITICAL)
281283
.setTitle(VULNERABILITY_REPORT_TITLE)
282284
.setDescription(VULNERABILITY_REPORT_DESCRIPTION)

doyensec/detectors/comfyui_preauth_rce/src/test/java/com/google/tsunami/plugins/detectors/comfyui/rce/ComfyUiRemoteCodeExecutionTest.java

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -142,7 +142,9 @@ private DetectionReport generateDetectionReport(
142142
.setVulnerability(
143143
Vulnerability.newBuilder()
144144
.setMainId(
145-
VulnerabilityId.newBuilder().setPublisher(VULNERABILITY_REPORT_PUBLISHER))
145+
VulnerabilityId.newBuilder()
146+
.setPublisher(VULNERABILITY_REPORT_PUBLISHER)
147+
.setValue("COMFYUI_2025_PREAUTH_RCE"))
146148
.setSeverity(Severity.CRITICAL)
147149
.setTitle(VULNERABILITY_REPORT_TITLE)
148150
.setDescription(VULNERABILITY_REPORT_DESCRIPTION)

0 commit comments

Comments
 (0)