PT-2021-23627 · Rasa · Rasa X
Rasa-Jmac
·
Published
2021-10-22
·
Updated
2021-10-28
·
CVE-2021-42556
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Rasa X versions prior to 0.42.4
Description
The issue allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.
Recommendations
For versions prior to 0.42.4, update to version 0.42.4 or later to resolve the issue. As a temporary workaround, consider restricting the functionality that allows users to load trained model archives until a patch is applied. Avoid using crafted archive files that could exploit the Directory Traversal vulnerability.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rasa X