PT-2023-24763 · Gradio · Gradio
Mastomii
·
Published
2023-06-07
·
Updated
2023-06-21
·
CVE-2023-34239
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Gradio versions prior to 3.34.0
Description
Gradio, an open-source Python library for building machine learning and data science applications, has issues with path filtering and URL proxying. This allows users to access arbitrary files on machines running shared Gradio apps and use these machines to proxy arbitrary URLs. The problems have been addressed in version 3.34.0.
Recommendations
For Gradio versions prior to 3.34.0, upgrade to version 3.34.0 or higher to resolve the issue. As a temporary workaround, consider taking down any shared Gradio apps until the upgrade is applied.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gradio