PT-2024-29658 · Haystack+1 · Haystack+1

Silvanocerza

·

Published

2024-07-31

·

Updated

2024-08-01

·

CVE-2024-41950

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Haystack versions prior to 2.3.1
Description The issue concerns Haystack clients that allow users to create and run Pipelines from scratch, making them vulnerable to remote code executions. Certain components in Haystack utilize Jinja2 templates. If an individual can create and render these templates on the client machine, they can execute any code.
Recommendations For versions prior to 2.3.1, update to Haystack version 2.3.1 to resolve the issue. As a temporary workaround, consider preventing users from running the affected components or only letting users use preselected templates.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-41950
GHSA-HX9V-6R9F-W677

Affected Products

Haystack
Jinja2