One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 8313021
Date de publication 2023-02-23 22:15:11 (vue: 2023-02-24 00:08:17)
Titre CVE-2023-25823
Texte Gradio is an open-source Python library to build machine learning and data science demos and web applications. Versions prior to 3.13.1 contain Use of Hard-coded Credentials. When using Gradio's share links (i.e. creating a Gradio app and then setting `share=True`), a private SSH key is sent to any user that connects to the Gradio machine, which means that a user could access other users' shared Gradio demos. From there, other exploits are possible depending on the level of access/exposure the Gradio app provides. This issue is patched in version 3.13.1, however, users are recommended to update to 3.19.1 or later where the FRP solution has been properly tested.
Notes
Envoyé Oui
Condensat 2023 25823 `share=true` access access/exposure any app applications are been build coded connects contain could creating credentials cve data demos depending exploits from frp gradio hard has however issue key later learning level library links machine means open other patched possible prior private properly provides python recommended science sent setting share shared solution source ssh tested then update use user users using version versions web when where which
Tags
Stories
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: