diff --git a/advisories/unreviewed/2024/04/GHSA-g9cj-cfpp-4g2x/GHSA-g9cj-cfpp-4g2x.json b/advisories/github-reviewed/2024/04/GHSA-g9cj-cfpp-4g2x/GHSA-g9cj-cfpp-4g2x.json similarity index 73% rename from advisories/unreviewed/2024/04/GHSA-g9cj-cfpp-4g2x/GHSA-g9cj-cfpp-4g2x.json rename to advisories/github-reviewed/2024/04/GHSA-g9cj-cfpp-4g2x/GHSA-g9cj-cfpp-4g2x.json index af0141aa4a7..835325e8997 100644 --- a/advisories/unreviewed/2024/04/GHSA-g9cj-cfpp-4g2x/GHSA-g9cj-cfpp-4g2x.json +++ b/advisories/github-reviewed/2024/04/GHSA-g9cj-cfpp-4g2x/GHSA-g9cj-cfpp-4g2x.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-g9cj-cfpp-4g2x", - "modified": "2024-04-16T00:30:33Z", + "modified": "2024-04-16T18:21:39Z", "published": "2024-04-16T00:30:33Z", "aliases": [ "CVE-2024-1561" ], + "summary": "gradio vulnerable to Path Traversal", "details": "An issue was discovered in gradio-app/gradio, where the `/component_server` endpoint improperly allows the invocation of any method on a `Component` class with attacker-controlled arguments. Specifically, by exploiting the `move_resource_to_block_cache()` method of the `Block` class, an attacker can copy any file on the filesystem to a temporary directory and subsequently retrieve it. This vulnerability enables unauthorized local file read access, posing a significant risk especially when the application is exposed to the internet via `launch(share=True)`, thereby allowing remote attackers to read files on the host machine. Furthermore, gradio apps hosted on `huggingface.co` are also affected, potentially leading to the exposure of sensitive information such as API keys and credentials stored in environment variables.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "gradio" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "4.13.0" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/gradio-app/gradio/commit/24a583688046867ca8b8b02959c441818bdb34a2" }, + { + "type": "PACKAGE", + "url": "https://github.com/gradio-app/gradio" + }, { "type": "WEB", "url": "https://huntr.com/bounties/4acf584e-2fe8-490e-878d-2d9bf2698338" @@ -35,8 +58,8 @@ "CWE-29" ], "severity": "HIGH", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-16T18:21:39Z", "nvd_published_at": "2024-04-16T00:15:08Z" } } \ No newline at end of file diff --git a/advisories/unreviewed/2024/04/GHSA-hq88-wg7q-gp4g/GHSA-hq88-wg7q-gp4g.json b/advisories/github-reviewed/2024/04/GHSA-hq88-wg7q-gp4g/GHSA-hq88-wg7q-gp4g.json similarity index 69% rename from advisories/unreviewed/2024/04/GHSA-hq88-wg7q-gp4g/GHSA-hq88-wg7q-gp4g.json rename to advisories/github-reviewed/2024/04/GHSA-hq88-wg7q-gp4g/GHSA-hq88-wg7q-gp4g.json index 369750ffb35..94f46e3f181 100644 --- a/advisories/unreviewed/2024/04/GHSA-hq88-wg7q-gp4g/GHSA-hq88-wg7q-gp4g.json +++ b/advisories/github-reviewed/2024/04/GHSA-hq88-wg7q-gp4g/GHSA-hq88-wg7q-gp4g.json @@ -1,11 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-hq88-wg7q-gp4g", - "modified": "2024-04-16T00:30:34Z", + "modified": "2024-04-16T18:20:36Z", "published": "2024-04-16T00:30:34Z", "aliases": [ "CVE-2024-3573" ], + "summary": "mlflow vulnerable to Path Traversal", "details": "mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_local_uri' function's failure to properly handle URIs with empty or 'file' schemes, leading to the misclassification of URIs as non-local. Attackers can exploit this by crafting malicious model versions with specially crafted 'source' parameters, enabling the reading of sensitive files within at least two directory levels from the server's root.", "severity": [ { @@ -14,7 +15,25 @@ } ], "affected": [ - + { + "package": { + "ecosystem": "PyPI", + "name": "mlflow" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + }, + { + "fixed": "2.10.0" + } + ] + } + ] + } ], "references": [ { @@ -25,6 +44,10 @@ "type": "WEB", "url": "https://github.com/mlflow/mlflow/commit/438a450714a3ca06285eeea34bdc6cf79d7f6cbc" }, + { + "type": "PACKAGE", + "url": "https://github.com/mlflow/mlflow" + }, { "type": "WEB", "url": "https://huntr.com/bounties/8ea058a7-4ef8-4baf-9198-bc0147fc543c" @@ -35,8 +58,8 @@ "CWE-29" ], "severity": "CRITICAL", - "github_reviewed": false, - "github_reviewed_at": null, + "github_reviewed": true, + "github_reviewed_at": "2024-04-16T18:20:36Z", "nvd_published_at": "2024-04-16T00:15:12Z" } } \ No newline at end of file