CVE-2024-1729
Dashboard / Vulnerabilities / CVE-2024-1729
CVE-2024-1729
Summary: Timing Attack Vulnerability in gradio-app/gradio
Details: A timing attack vulnerability exists in the gradio-app/gradio repository, specifically within the login function in routes.py. The vulnerability arises from the use of a direct comparison operation (`app.auth[username] == password`) to validate user credentials, which can be exploited to guess passwords based on response times. Successful exploitation of this vulnerability could allow an attacker to bypass authentication mechanisms and gain unauthorized access.
References: https://huntr.com/bounties/f6a10a8d-f538-4cb7-9bb2-85d9f5708124, https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1729.json, https://nvd.nist.gov/vuln/detail/CVE-2024-1729, https://github.com/gradio-app/gradio/commit/e329f1fd38935213fe0e73962e8cbd5d3af6e87b
Affected packages
Package
Name:
Purl:
Affected ranges
Type: GIT
Events:
