Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40966
HistoryJun 21, 2023 - 2:38 a.m.

Path Traversal

2023-06-2102:38:36
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
gradio
path traversal
proxy urls
arbitrary files
security

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

51.1%

gradio is vulnerable to Path Traversal. The vulnerability exists because the library does not properly restrict the proxy URLs, which allows an attacker to access and read arbitrary files outside the expected directory through the malicious proxy URL.

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

EPSS

0.001

Percentile

51.1%

Related for VERACODE:40966