PT-2024-24518 · Gradio+1 · Gradio+1
Published
2024-06-06
·
Updated
2025-04-07
·
CVE-2024-3234
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
gaizhenbiao/chuanhuchatgpt versions prior to the fixed version released on 20240305
Description
The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. This vulnerability allows unauthorized users to bypass the intended restrictions and access sensitive files, such as
config.json, which contains API keys. The application is designed to restrict user access to resources within the web assets folder, but the outdated version of gradio it employs is susceptible to path traversal.Recommendations
For versions prior to the fixed version released on 20240305, update to the latest version to resolve the issue. As a temporary workaround, consider restricting access to sensitive files, such as
config.json, until the update is applied.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gaizhenbiao/Chuanhuchatgpt
Gradio