Miggo Logo

CVE-2024-47166: Gradio has a one-level read path traversal in `/custom_component`

5.3

CVSS Score
3.1

Basic Information

EPSS Score
0.38803%
Published
10/10/2024
Updated
1/21/2025
KEV Status
No
Technology
TechnologyPython

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
gradiopip< 4.44.04.44.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t **W**t kin* o* vuln*r**ility is it? W*o is imp**t**?** T*is vuln*r**ility involv*s * **on*-l*v*l r*** p*t* tr*v*rs*l** in t** `/*ustom_*ompon*nt` *n*point. *tt**k*rs **n *xploit t*is *l*w to ****ss *n* l**k sour** *o** *rom *ustom *r**i

Reasoning

No *n*lysis *v*il**l*