PT-2023-24763 · Gradio · Gradio

Mastomii

·

Published

2023-06-07

·

Updated

2023-06-21

·

CVE-2023-34239

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Gradio versions prior to 3.34.0
Description Gradio, an open-source Python library for building machine learning and data science applications, has issues with path filtering and URL proxying. This allows users to access arbitrary files on machines running shared Gradio apps and use these machines to proxy arbitrary URLs. The problems have been addressed in version 3.34.0.
Recommendations For Gradio versions prior to 3.34.0, upgrade to version 3.34.0 or higher to resolve the issue. As a temporary workaround, consider taking down any shared Gradio apps until the upgrade is applied.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-34239
GHSA-3QQG-PGQQ-3695
PYSEC-2023-90

Affected Products

Gradio