Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3gf9-wv65-gwh9

Опубликовано: 05 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.7
CVSS3: 6.5

Описание

gradio Server Side Request Forgery vulnerability

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.

Пакеты

Наименование

gradio

pip
Затронутые версииВерсия исправления

<= 4.42.0

Отсутствует

EPSS

Процентиль: 26%
0.00092
Низкий

5.7 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
nvd
больше 1 года назад

In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.

EPSS

Процентиль: 26%
0.00092
Низкий

5.7 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-918