PT-2024-29970 · Streamlit · Streamlit
Nvn1729
·
Published
2024-08-12
·
Updated
2024-09-16
·
CVE-2024-42474
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Streamlit versions prior to 1.37.0
Description
The issue is related to a path traversal vulnerability in the static file sharing feature of Streamlit. This vulnerability allows an attacker to leak the password hash of the Windows user running Streamlit when the static file sharing feature is enabled. The vulnerability only affects Windows.
Recommendations
For versions prior to 1.37.0, upgrade to version 1.37.0 to resolve the issue. As a temporary workaround, consider disabling the static file sharing feature until the patch is applied. Restrict access to the static file sharing feature to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Streamlit