CVE-2021-42556

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
22/10/2021
Last modified:
28/10/2021

Description

Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rasa:rasa_x:*:*:*:*:*:*:*:* 0.42.4 (excluding)