Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Rasa X before 0.42.4 allows Directory Traversal during archive extraction. In the functionality that allows a user to load a trained model archive, an attacker has arbitrary write capability within specific directories via a crafted archive file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Rasa 路径遍历漏洞
Vulnerability Description
Rasa是一个开源机器学习框架,用于自动化基于文本和语音的对话。 Rasa X 存在安全漏洞,该漏洞源于0.42.4之前的Rasa X允许在归档提取期间遍历目录。攻击者可利用该漏洞通过精心制作的存档文件在特定目录中具有任意写入功能。
CVSS Information
N/A
Vulnerability Type
N/A