Observable Discrepancy
CVE-2024-47869
Summary
Gradio is an open-source Python package designed for quick prototyping. This vulnerability involves a Timing Attack in the way Gradio compares hashes for the "analytics_dashboard" function. Since the comparison is not done in constant time, an attacker could exploit this by measuring the response time of different requests to infer the correct hash "byte-by-byte". This can lead to unauthorized access to the analytics dashboard, especially if the attacker can repeatedly query the system with different keys. This vulnerability affects gradio package versions prior to 4.44.0. Users are advised to upgrade to a fixed version to mitigate this issue. To mitigate the risk before applying the patch, developers can manually patch the "analytics_dashboard`" dashboard to use a "constant-time comparison" function for comparing sensitive values, such as hashes. Alternatively, access to the analytics dashboard can be disabled.
- HIGH
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- LOW
- NONE
CWE-203 - Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
References
Advisory Timeline
- Published