漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()
Vulnerability Description
Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplying path segments containing directory traversal sequences or absolute paths. Attackers can provide crafted path segments that cause os.path.join to discard the root_dir prefix entirely, resulting in arbitrary file read or exposure of sensitive files outside the intended directory.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
gradio-app gradio 路径遍历漏洞
Vulnerability Description
gradio-app gradio是gradio-app的机器学习Web演示框架。 gradio-app gradio 6.16.0之前版本存在路径遍历漏洞,该漏洞源于FileExplorer组件的preprocess()方法存在路径遍历问题,攻击者可以通过提供包含目录遍历序列或绝对路径的路径段,导致os.path.join完全丢弃root_dir前缀,从而逃逸配置的根目录,实现任意文件读取或暴露预期目录之外敏感文件。
CVSS Information
N/A
Vulnerability Type
N/A