PT-2025-12126 · Gradio · Gradio

Publicado

2024-11-10

·

Atualizado

2025-03-20

·

CVE-2024-12217

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions gradio-app/gradio version git 67e4044
Description A flaw in the implementation of the blocked path functionality allows for path traversal on Windows OS. The application fails to block access when using NTFS Alternate Data Streams (ADS) syntax, such as 'C:/tmp/secret.txt::$DATA', which can lead to unauthorized reading of blocked file paths.
Recommendations For version git 67e4044, consider disabling the blocked path functionality until a patch is available to prevent path traversal attacks. Restrict access to sensitive files and directories to minimize the risk of exploitation. Avoid using NTFS Alternate Data Streams (ADS) syntax in file paths to prevent bypassing the blocked path functionality.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-01839
CVE-2024-12217
GHSA-PRPG-P95C-32FV

Produtos afetados

Gradio