Lucene search

K
cveMitreCVE-2023-41626
HistorySep 15, 2023 - 11:15 p.m.

CVE-2023-41626

2023-09-1523:15:07
CWE-434
mitre
web.nvd.nist.gov
14
cve-2023-41626
gradio
v3.27.0
arbitrary file upload
vulnerability
upload interface
nvd

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

28.0%

Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface.

Affected configurations

Nvd
Node
gradio_projectgradioMatch3.27.0python
VendorProductVersionCPE
gradio_projectgradio3.27.0cpe:2.3:a:gradio_project:gradio:3.27.0:*:*:*:*:python:*:*

CVSS3

4.8

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.001

Percentile

28.0%