PT-2021-23110 · Rasa · Rasa

Rasa-Jmac

·

Published

2021-10-21

·

Updated

2021-10-27

·

CVE-2021-41127

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rasa versions prior to 2.8.10
Description A vulnerability exists in the functionality that loads a trained model tar.gz file, allowing a malicious actor to craft a model.tar.gz file that can overwrite or replace bot files in the bot directory. This issue enables an attacker to have arbitrary write capability within specific directories using a maliciously crafted archive file.
Recommendations For versions prior to 2.8.10, update to Rasa 2.8.10 to fix the vulnerability. As a temporary workaround for users unable to update, ensure that users do not upload untrusted model files, and restrict CLI or API endpoint access where a malicious actor could target a deployed Rasa instance.

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41127
GHSA-4365-FHM5-QCRX
PYSEC-2021-381

Affected Products

Rasa