github.com
https://github.com/gradio-app/gradio CVE-2024-1727
CSRF Vulnerability in gradio-app/gradio
Description
A Cross-Site Request Forgery (CSRF) vulnerability in gradio-app/gradio allows attackers to upload multiple large files to a victim's system if they are running Gradio locally. By crafting a malicious HTML page that triggers an unauthorized file upload to the victim's server, an attacker can deplete the system's disk space, potentially leading to a denial of service. This issue affects the file upload functionality as implemented in gradio/routes.py.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2024 · Source: CVE List
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
gradio-app/gradioBrowse gradio-app / gradio-app/gradio | CVE List | Before 4.19.2 | affected |
Default status: unknown | CVE List | 4.16.0 | affected |
gradioBrowse PyPI / gradio | GitHub Advisory | Before 4.19.2 · Fixed in 4.19.2 | affected |
References
6github.com
https://github.com/gradio-app/gradio/commit/84802ee6a4806c25287344dce581f9548a99834a github.com
https://github.com/gradio-app/gradio/pull/7503 github.com
https://github.com/gradio-app/gradio/security/advisories/GHSA-48cq-79qq-6f7x huntr.com
https://huntr.com/bounties/a94d55fb-0770-4cbe-9b20-97a978a2ffff nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-1727