Gradio is an open-source Python... CVE-2023-51449

- AV AC AU C I A
发布: 2023-12-22
修订: 2024-01-09

Gradio is an open-source Python package that allows you to quickly build a demo or web application for your machine learning model, API, or any arbitary Python function. Versions of `gradio` prior to 4.11.0 contained a vulnerability in the `/file` route which made them susceptible to file traversal attacks in which an attacker could access arbitrary files on a machine running a Gradio app with a public URL (e.g. if the demo was created with `share=True`, or on Hugging Face Spaces) if they knew the path of files to look for. This issue has been patched in version 4.11.0.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息