Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45386
HistoryFeb 07, 2024 - 6:07 a.m.

Path Traversal

2024-02-0706:07:56
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
gradio
path traversal
json
api
filesystem
vulnerability
security issue

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

47.3%

Gradio is vulnerable to Path Traversal. The vulnerability is due to improper validation when parsing a user supplied JSON value inan API request. This issue can be exploited by an attacker read am arbitrary file on the filesystem.

CVSS3

9.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

AI Score

6.7

Confidence

High

EPSS

0.001

Percentile

47.3%