An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.
References
Link | Resource |
---|---|
https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888 | Exploit Third Party Advisory |
https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888 | Exploit Third Party Advisory |
Configurations
History
26 Mar 2025, 16:39
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888 - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:gradio_project:gradio:-:*:*:*:*:python:*:* | |
First Time |
Gradio Project gradio
Gradio Project |
|
Summary |
|
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.1 |
20 Mar 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888 - |
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-03-26 16:39
NVD link : CVE-2024-8021
Mitre link : CVE-2024-8021
CVE.ORG link : CVE-2024-8021
JSON object : View
Products Affected
gradio_project
- gradio
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')