漏洞描述 Gradio-app是一个用于构建和分享机器学习应用模型的开源工具,旨在通过网页界面展示机器学习模型。Gradio存在SSRF漏洞,允许攻击者通过在urlparameter中注入特制的URL来迫使应用程序进行任意请求。
相关漏洞推荐 POC gradio-image-ssrf: Gradio Image Component - Server-Side Request Forgery POC gradio-lfi: Gradio - Local File Inclusion gradio /queue/join 服务器端请求伪造漏洞(CVE-2024-4325) gradio /file 服务器端请求伪造漏洞(CVE-2024-1183) POC CVE-2021-43831: Gradio < 2.5.0 - Arbitrary File Read POC CVE-2023-51449: Gradio Hugging Face - Local File Inclusion POC CVE-2024-1183: Gradio - Server Side Request Forgery POC CVE-2024-1561: Gradio 4.3-4.12 - Local File Read POC CVE-2024-1728: Gradio > 4.19.1 UploadButton - Path Traversal POC CVE-2024-4325: Gradio - Server-Side Request Forgery POC CVE-2024-4940: Gradio - Open Redirect POC CVE-2024-8021: Gradio - Open Redirect POC gradio-component-server-lfi: Gradio 3.47/3.50.2 - Local File Inclusion