An SSRF (Server-Side Request... CVE-2024-1183

- AV AC AU C I A
发布: 2024-04-16
修订: 2024-04-16

An SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter in a GET request, an attacker can discern the status of internal ports based on the presence of a 'Location' header or a 'File not allowed' error in the response.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息