Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7v2w-h4gh-w5cv

Опубликовано: 20 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Gradio Vulnerable to Open Redirect

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.

Пакеты

Наименование

gradio

pip
Затронутые версииВерсия исправления

<= 4.37.2

Отсутствует

EPSS

Процентиль: 85%
0.02682
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
nvd
11 месяцев назад

An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.

EPSS

Процентиль: 85%
0.02682
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-601