Lucene search

K
osvGoogleOSV:GHSA-F3H9-8PHC-6GVH
HistoryFeb 06, 2024 - 12:30 a.m.

Gradio Path Traversal vulnerability

2024-02-0600:30:28
Google
osv.dev
6
gradio
path traversal
json
api
vulnerability
remote trigger

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS

0.001

Percentile

47.3%

A local file include could be remotely triggered in Gradio due to a vulnerable user-supplied JSON value in an API request.

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

EPSS

0.001

Percentile

47.3%