CVE-2024-49375

CVSS 3.1 Score 9 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 94
CWE ID 502

Summary

CVE-2024-49375: A critical Remote Code Execution (RCE) vulnerability has been discovered in the open-source machine learning framework Rasa. An attacker with access to load a maliciously crafted model into a Rasa instance can exploit this vulnerability if the HTTP API is enabled (not the default) and no authentication or security controls are in place. For authenticated RCE, an attacker needs a valid authentication token or JWT. Rasa versions prior to 3.6.21 are affected. All users are advised to upgrade or enforce authentication and access controls to mitigate risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share