CVE-2024-10648
8.2
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Exploitability: 3.9 / Impact: 4.2
Source: security@huntr.dev (Secondary)
Description
A path traversal vulnerability exists in the Gradio Audio component of gradio-app/gradio, as of version git 98cbcae. This vulnerability allows an attacker to control the format of the audio file, leading to arbitrary file content deletion. By manipulating the output format, an attacker can reset any file to an empty file, causing a denial of service (DOS) on the server.
Affected (1)
Products: Gradio Project: Gradio
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2024-09-18 |
References (1)
Source: security@huntr.dev
ExploitThird Party Advisory
Timeline
No history available yet.