CVE-2021-41127: Maliciously Crafted Model Archive Can Lead To Arbitrary File Write
(updated )
An Archive Extraction (Zip Slip) vulnerability in the functionality that allows a user to load a trained model archive in Rasa 2.8.9 and older allows an attacker arbitrary write capability within specific directories using a malicious crafted archive file.
References
- github.com/RasaHQ/rasa
- github.com/RasaHQ/rasa/commit/1b6b502f52d73b4f8cd1959ce724b8ad0eb33989
- github.com/RasaHQ/rasa/security/advisories/GHSA-4365-fhm5-qcrx
- github.com/advisories/GHSA-4365-fhm5-qcrx
- github.com/pypa/advisory-database/tree/main/vulns/rasa/PYSEC-2021-381.yaml
- nvd.nist.gov/vuln/detail/CVE-2021-41127
Detect and mitigate CVE-2021-41127 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →