PT-2021-23110 · Rasa · Rasa
Rasa-Jmac
·
Published
2021-10-21
·
Updated
2021-10-27
·
CVE-2021-41127
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rasa versions prior to 2.8.10
Description
A vulnerability exists in the functionality that loads a trained model
tar.gz file, allowing a malicious actor to craft a model.tar.gz file that can overwrite or replace bot files in the bot directory. This issue enables an attacker to have arbitrary write capability within specific directories using a maliciously crafted archive file.Recommendations
For versions prior to 2.8.10, update to Rasa 2.8.10 to fix the vulnerability.
As a temporary workaround for users unable to update, ensure that users do not upload untrusted model files, and restrict CLI or API endpoint access where a malicious actor could target a deployed Rasa instance.
Fix
Relative Path Traversal
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rasa