CVE-2023-51449

CVSS V2 None CVSS V3 None
Description
Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to 4.11.0 contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with `share=True`, or on Hugging Face Spaces) if they knew the path of files to look for. This issue has been patched in version 4.11.0.
Overview
  • CVE ID
  • CVE-2023-51449
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-12-22T20:58:36.185Z
  • Last Modified Date
  • 2024-06-20T18:27:57.779Z
History
Created Old Value New Value Data Type Notes
2024-06-24 18:32:26 Added to TrackCVE