CVE-2024-49375
CVSS 3.1 Score 9 of 10 (high)
Details
Summary
CVE-2024-49375: A critical Remote Code Execution (RCE) vulnerability has been discovered in the open-source machine learning framework Rasa. An attacker with access to load a maliciously crafted model into a Rasa instance can exploit this vulnerability if the HTTP API is enabled (not the default) and no authentication or security controls are in place. For authenticated RCE, an attacker needs a valid authentication token or JWT. Rasa versions prior to 3.6.21 are affected. All users are advised to upgrade or enforce authentication and access controls to mitigate risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.