Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-1728

Опубликовано: 10 апр. 2024
Источник: nvd
CVSS3: 7.5
CVSS3: 7.5
EPSS Высокий

Описание

gradio-app/gradio is vulnerable to a local file inclusion vulnerability due to improper validation of user-supplied input in the UploadButton component. Attackers can exploit this vulnerability to read arbitrary files on the filesystem, such as private SSH keys, by manipulating the file path in the request to the /queue/join endpoint. This issue could potentially lead to remote code execution. The vulnerability is present in the handling of file upload paths, allowing attackers to redirect file uploads to unintended locations on the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gradio_project:gradio:*:*:*:*:*:python:*:*
Версия от 4.18.0 (включая) до 4.19.2 (исключая)

EPSS

Процентиль: 99%
0.81897
Высокий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
github
больше 1 года назад

Gradio allows users to access arbitrary files

EPSS

Процентиль: 99%
0.81897
Высокий

7.5 High

CVSS3

7.5 High

CVSS3

Дефекты

CWE-22