Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
|  EUVD | EUVD-2024-0066 | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when monitoring is supposedly disabled, an attacker or unauthorized user can still access the monitoring dashboard by directly requesting the /monitoring endpoint. This means that sensitive application analytics may still be exposed, particularly in environments where monitoring is expected to be disabled. Users who set enable_monitoring=False to prevent unauthorized access to monitoring data are impacted. Users are advised to upgrade to gradio>=4.44 to address this issue. There are no known workarounds for this vulnerability. | 
|  Github GHSA | GHSA-hm3c-93pg-4cxw | In Gradio, the `enable_monitoring` flag set to `False` does not disable monitoring | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 17 Oct 2024 17:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Gradio Project Gradio Project gradio | |
| CPEs | cpe:2.3:a:gradio_project:gradio:*:*:*:*:*:python:*:* | |
| Vendors & Products | Gradio Project Gradio Project gradio | |
| Metrics | cvssV3_1 
 | 
Fri, 11 Oct 2024 21:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 10 Oct 2024 22:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves data exposure due to the enable_monitoring flag not properly disabling monitoring when set to False. Even when monitoring is supposedly disabled, an attacker or unauthorized user can still access the monitoring dashboard by directly requesting the /monitoring endpoint. This means that sensitive application analytics may still be exposed, particularly in environments where monitoring is expected to be disabled. Users who set enable_monitoring=False to prevent unauthorized access to monitoring data are impacted. Users are advised to upgrade to gradio>=4.44 to address this issue. There are no known workarounds for this vulnerability. | |
| Title | The `enable_monitoring` flag set to `False` does not disable monitoring in Gradio | |
| Weaknesses | CWE-670 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-11T15:28:22.945Z
Reserved: 2024-09-19T22:32:11.960Z
Link: CVE-2024-47168
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-10-11T15:28:18.494Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-10-10T22:15:11.173
Modified: 2024-10-17T17:00:47.057
Link: CVE-2024-47168
 Redhat
                        Redhat
                    No data.
 OpenCVE Enrichment
                        OpenCVE Enrichment
                    No data.