PT-2024-29970 · Streamlit · Streamlit

Nvn1729

·

Published

2024-08-12

·

Updated

2024-09-16

·

CVE-2024-42474

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Streamlit versions prior to 1.37.0
Description The issue is related to a path traversal vulnerability in the static file sharing feature of Streamlit. This vulnerability allows an attacker to leak the password hash of the Windows user running Streamlit when the static file sharing feature is enabled. The vulnerability only affects Windows.
Recommendations For versions prior to 1.37.0, upgrade to version 1.37.0 to resolve the issue. As a temporary workaround, consider disabling the static file sharing feature until the patch is applied. Restrict access to the static file sharing feature to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-42474
GHSA-RXFF-VR5R-8CJ5
PYSEC-2024-153

Affected Products

Streamlit