PT-2024-29658 · Haystack+1 · Haystack+1
Silvanocerza
·
Published
2024-07-31
·
Updated
2024-08-01
·
CVE-2024-41950
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Haystack versions prior to 2.3.1
Description
The issue concerns Haystack clients that allow users to create and run Pipelines from scratch, making them vulnerable to remote code executions. Certain components in Haystack utilize Jinja2 templates. If an individual can create and render these templates on the client machine, they can execute any code.
Recommendations
For versions prior to 2.3.1, update to Haystack version 2.3.1 to resolve the issue.
As a temporary workaround, consider preventing users from running the affected components or only letting users use preselected templates.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Haystack
Jinja2