Record summary

CVE-2024-1183 has a selected CVSS score of 6.5 (medium); EIP currently links 1 Nuclei template.

Description

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a 'Location' header or a 'File not allowed' error in the response.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 20, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE ListBefore 4.11affected

Default status: unknown

CVE ListBefore 4.11affected
GitHub AdvisoryBefore 4.10.0 · Fixed in 4.10.0affected

Nuclei templates

1
ProjectDiscoveryMEDIUMGradio - Server Side Request ForgeryCVSS 6.5

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a 'Location' header or a 'File not allowed' error in the response.

Impact

Unauthenticated attackers can perform SSRF attacks to scan and identify open ports within internal networks, potentially facilitating further attacks.

Remediation

Upgrade Gradio to version 3.33 or later (for Gradio < 3.x) or version 4.11 or later (for Gradio 4.x).

WeaknessesCWE-601
AuthorsDhiyaneshDK
Template tagscvecve2024ssrfoastgradiovuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:gradio_project:gradio:*:*:*:*:python:*:*:*
Shodan: html:"__gradio_mode__"

Source: ProjectDiscovery

References

5