Vulnerability Description
An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited by sending a crafted request to the application, which results in a 302 redirect to an attacker-controlled site.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gradio Project | Gradio | - |
Related Weaknesses (CWE)
References
- https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888ExploitThird Party Advisory
- https://huntr.com/bounties/adc23067-ec04-47ef-9265-afd452071888ExploitThird Party Advisory
FAQ
What is CVE-2024-8021?
CVE-2024-8021 is a vulnerability with a CVSS score of 6.1 (MEDIUM). An open redirect vulnerability exists in the latest version of gradio-app/gradio. The vulnerability allows an attacker to redirect users to a malicious website by URL encoding. This can be exploited b...
How severe is CVE-2024-8021?
CVE-2024-8021 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-8021?
Check the references section above for vendor advisories and patch information. Affected products include: Gradio Project Gradio.