CVE-2024-8501
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2024-8501 is a newly identified arbitrary file download vulnerability affecting the rpc_agent_client component of modelscope/agentscope version v0.0.4. This issue enables any user to download any file from the rpc_agent's host by manipulating the download_file method. The consequences of this vulnerability can be severe, as it may result in unauthorized access to sensitive information, such as configuration files, credentials, and system files. Potentially, this could provide an attacker with the means to escalate privileges or move laterally within a network, increasing the risk of further security breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.