GHSA-4365-fhm5-qcrx
Dashboard / Vulnerabilities / GHSA-4365-fhm5-qcrx
GHSA-4365-fhm5-qcrx
Summary: Maliciously Crafted Model Archive Can Lead To Arbitrary File Write
Details: ### Impact An Archive Extraction (Zip Slip) vulnerability in the functionality that allows a user to load a trained model archive in Rasa 2.8.9 and older allows an attacker arbitrary write capability within specific directories using a malicious crafted archive file. ### Patches The vulnerability is fixed in Rasa 2.8.10 ### Workarounds Mitigating steps for vulnerable end users are to ensure that they do not upload untrusted model files, and restrict CLI or API endpoint access where a malicious actor could target a deployed Rasa instance. ### For more information If you have any questions or comments about this advisory: * Email [the Rasa Security Team](mailto:[email protected])
References: https://github.com/RasaHQ/rasa/security/advisories/GHSA-4365-fhm5-qcrx, https://github.com/RasaHQ/rasa/commit/1b6b502f52d73b4f8cd1959ce724b8ad0eb33989, https://github.com/RasaHQ/rasa, https://github.com/pypa/advisory-database/tree/main/vulns/rasa/PYSEC-2021-381.yaml
Affected packages
Package
Name: rasa
Purl: pkg:pypi/rasa
Affected ranges
Type: ECOSYSTEM
Events:
