Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-973g-55hp-3frw

Опубликовано: 06 июн. 2024
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Server-Side Request Forgery in gradio

A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio and was discovered in version 4.21.0, specifically within the /queue/join endpoint and the save_url_to_cache function. The vulnerability arises when the path value, obtained from the user and expected to be a URL, is used to make an HTTP request without sufficient validation checks. This flaw allows an attacker to send crafted requests that could lead to unauthorized access to the local network or the AWS metadata endpoint, thereby compromising the security of internal servers.

Пакеты

Наименование

gradio

pip
Затронутые версииВерсия исправления

<= 4.36.0

Отсутствует

EPSS

Процентиль: 98%
0.4767
Средний

8.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
nvd
больше 1 года назад

A Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` function. The vulnerability arises when the `path` value, obtained from the user and expected to be a URL, is used to make an HTTP request without sufficient validation checks. This flaw allows an attacker to send crafted requests that could lead to unauthorized access to the local network or the AWS metadata endpoint, thereby compromising the security of internal servers.

EPSS

Процентиль: 98%
0.4767
Средний

8.6 High

CVSS3

Дефекты

CWE-918