[Bug 1223928] New: VUL-0: CVE-2024-34511: gradio: server component does not properly consider _is_server_fn for functions
![](https://seccdn.libravatar.org/avatar/a895f78a81a109471893519443e4d933.jpg?s=120&d=mm&r=g)
https://bugzilla.suse.com/show_bug.cgi?id=1223928 Bug ID: 1223928 Summary: VUL-0: CVE-2024-34511: gradio: server component does not properly consider _is_server_fn for functions Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.6 Hardware: Other URL: https://smash.suse.de/issue/404394/ OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: dmueller@suse.com Reporter: smash_bz@suse.de QA Contact: security-team@suse.de CC: carlos.lopez@suse.com Target Milestone: --- Found By: Security Response Team Blocker: --- Component Server in Gradio before 4.13 does not properly consider _is_server_fn for functions. References: https://github.com/gradio-app/gradio/ http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-34511 https://www.cve.org/CVERecord?id=CVE-2024-34511 https://www.gradio.app/changelog#4-13-0 -- You are receiving this mail because: You are on the CC list for the bug.
![](https://seccdn.libravatar.org/avatar/a895f78a81a109471893519443e4d933.jpg?s=120&d=mm&r=g)
https://bugzilla.suse.com/show_bug.cgi?id=1223928
Carlos López
![](https://seccdn.libravatar.org/avatar/a895f78a81a109471893519443e4d933.jpg?s=120&d=mm&r=g)
https://bugzilla.suse.com/show_bug.cgi?id=1223928
Maintenance Automation
![](https://seccdn.libravatar.org/avatar/a895f78a81a109471893519443e4d933.jpg?s=120&d=mm&r=g)
https://bugzilla.suse.com/show_bug.cgi?id=1223928
https://bugzilla.suse.com/show_bug.cgi?id=1223928#c2
Dirk Mueller
![](https://seccdn.libravatar.org/avatar/a895f78a81a109471893519443e4d933.jpg?s=120&d=mm&r=g)
https://bugzilla.suse.com/show_bug.cgi?id=1223928
https://bugzilla.suse.com/show_bug.cgi?id=1223928#c3
Carlos López
I think this is a different gradio than what we're shipping. what we're shipping is https://github.com/haecker-felix/gradio - thjis is about https://github.com/gradio-app/gradio/
You're right. Closing. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com