SCA: security update for gradio (GHSA-8c87-gvhj-xm8m)

high Tenable Self-Hosted Container Security Plugin ID 412588

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Gradio is an open-source Python package designed for quick prototyping. This vulnerability is a **lack of
integrity check** on the downloaded FRP client, which could potentially allow attackers to introduce
malicious code. If an attacker gains access to the remote URL from which the FRP client is downloaded,
they could modify the binary without detection, as the Gradio server does not verify the file's checksum
or signature. Any users utilizing the Gradio server's sharing mechanism that downloads the FRP client
could be affected by this vulnerability, especially those relying on the executable binary for secure data
tunneling. There is no direct workaround for this issue without upgrading. However, users can manually
validate the integrity of the downloaded FRP client by implementing checksum or signature verification in
their own environment to ensure the binary hasn't been tampered with. (CVE-2024-47867)

See Also

https://github.com/advisories/GHSA-8c87-gvhj-xm8m

Plugin Details

Severity: High

ID: 412588

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2024-47867

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.5

Threat Score: 4.8

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/10/2024

Vulnerability Publication Date: 10/10/2024

Reference Information

CVE: CVE-2024-47867