Bugzilla – Bug 1215419
VUL-0: CVE-2023-41626: gradio: arbitrary file upload via /upload endpoint
Last modified: 2023-09-29 11:11:31 UTC
CVE-2023-41626 Gradio v3.27.0 was discovered to contain an arbitrary file upload vulnerability via the /upload interface. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-41626 https://www.cve.org/CVERecord?id=CVE-2023-41626 https://gist.github.com/impose1/590472eb0544ef1ec36c8a5a40122adb
Now I see that the upstream repo is archived and the readme at: https://github.com/haecker-felix/gradio states "The successor of Gradio is Shortwave." Upstream is at https://gitlab.gnome.org/World/Shortwave and someone packaged it: https://build.opensuse.org/package/show/home:Dead_Mozay:GNOME:Apps/shortwave Same upstream developer is active there. So I thought to remove Gradio and replace it by Shortwave. But then I realized that Gradio is actually not part of Factory anymore :) So I disabled the build in the devel repo and I think everything should be fine?
(In reply to Michael Vetter from comment #2) > But then I realized that Gradio is actually not part of Factory anymore :) > So I disabled the build in the devel repo and I think everything should be > fine? It's part of openSUSE:Backports:SLE-15-SP{4,5,6} though, right?
(In reply to Carlos López from comment #3) > (In reply to Michael Vetter from comment #2) > > But then I realized that Gradio is actually not part of Factory anymore :) > > So I disabled the build in the devel repo and I think everything should be > > fine? > > It's part of openSUSE:Backports:SLE-15-SP{4,5,6} though, right? Well the gradio internet radio player is. I checked the issue again. I was already confused about what upload functionality it should provide.. And now I realized the gist mentions https://www.gradio.app/ which is something machine learning and Python related. So it's not the same as the gradio application at https://github.com/haecker-felix/gradio where I maintained the openSUSE package :-) I would set this as invalid.
This issue affects a different application with the same name. Closing.