Gradio是一个开源 Python 库,是通过友好的 Web 界面演示机器学习模型的方法。 Gradio 存在安全漏洞,该漏洞源于端点不正确地允许调用类上的任何方法,允许未经授权的本地文件读取访问,可能导致敏感信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| gradio-app | gradio-app/gradio | unspecified ~ 4.13.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Poc for CVE-2024-1561 affecting Gradio 4.12.0 | https://github.com/DiabloHTB/CVE-2024-1561 | POC Details |
| 2 | Nuclei Templates | https://github.com/DiabloHTB/Nuclei-Template-CVE-2024-1561 | POC Details |
| 3 | Local file read by calling arbitrary methods of Components class between Gradio versions 4.3-4.12 | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-1561.yaml | POC Details |
| 4 | https://github.com/vulhub/vulhub/blob/master/gradio/CVE-2024-1561/README.md | POC Details | |
| 5 | None | https://github.com/Threekiii/Awesome-POC/blob/master/%E5%BC%80%E5%8F%91%E8%AF%AD%E8%A8%80%E6%BC%8F%E6%B4%9E/Python%20Gradio%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%20CVE-2024-1561.md | POC Details |
No public POC found.
Login to generate AI POCNo comments yet