PT-2023-24763 · Gradio · Gradio

Mastomii

·

Publicado

2023-06-07

·

Atualizado

2023-06-21

·

CVE-2023-34239

CVSS v3.1

7.3

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Gradio versions prior to 3.34.0
Description Gradio, an open-source Python library for building machine learning and data science applications, has issues with path filtering and URL proxying. This allows users to access arbitrary files on machines running shared Gradio apps and use these machines to proxy arbitrary URLs. The problems have been addressed in version 3.34.0.
Recommendations For Gradio versions prior to 3.34.0, upgrade to version 3.34.0 or higher to resolve the issue. As a temporary workaround, consider taking down any shared Gradio apps until the upgrade is applied.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-34239
GHSA-3QQG-PGQQ-3695
PYSEC-2023-90

Produtos afetados

Gradio