In gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions on the URL, which allows access to local target resources. This can lead to the download of local resources and sensitive information.
References
Configurations
No configuration.
History
06 Nov 2024, 20:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-918 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
05 Nov 2024, 16:04
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
04 Nov 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-04 23:15
Updated : 2024-11-06 20:35
NVD link : CVE-2024-48052
Mitre link : CVE-2024-48052
CVE.ORG link : CVE-2024-48052
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)