Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:46076
HistoryMar 29, 2024 - 8:23 a.m.

Server Side Request Forgery (SSRF)

2024-03-2908:23:34
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
13
server side request forgery
vulnerability
gradio
proxy route
arbitrary urls
internal endpoints
exploitation

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.0%

gradio is vulnerable to Server Side Request Forgery (SSRF). The vulnerability is due to the /proxy route allowing users to proxy arbitrary URLs include potentially internal endpoints. Attackers can proxy arbitrary URLs by exploiting this vulnerability.

CVSS3

7.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.0%