Логотип exploitDog
bind:CVE-2021-43831
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-43831

Количество 2

Количество 2

nvd логотип

CVE-2021-43831

около 4 лет назад

Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces. File paths are not restricted and users who receive a Gradio link can access any files on the host computer if they know the file names or file paths. This is limited only by the host operating system. Paths are opened in read only mode. The problem has been patched in gradio 2.5.0.

CVSS3: 7.7
EPSS: Средний
github логотип

GHSA-rhq2-3vr9-6mcr

около 4 лет назад

Files on the host computer can be accessed from the Gradio interface

CVSS3: 8.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-43831

Gradio is an open source framework for building interactive machine learning models and demos. In versions prior to 2.5.0 there is a vulnerability that affects anyone who creates and publicly shares Gradio interfaces. File paths are not restricted and users who receive a Gradio link can access any files on the host computer if they know the file names or file paths. This is limited only by the host operating system. Paths are opened in read only mode. The problem has been patched in gradio 2.5.0.

CVSS3: 7.7
30%
Средний
около 4 лет назад
github логотип
GHSA-rhq2-3vr9-6mcr

Files on the host computer can be accessed from the Gradio interface

CVSS3: 8.3
30%
Средний
около 4 лет назад

Уязвимостей на страницу