Code Injection Vulnerability in flairNLP's ClusteringModel Function
CVE-2024-10073

7.5HIGH

Key Information:

Vendor

Flairnlp

Status
Vendor
CVE Published:
17 October 2024

Badges

👾 Exploit Exists

What is CVE-2024-10073?

A significant code injection vulnerability has been discovered in flairNLP's flair product, specifically within the ClusteringModel function of the Mode File Loader component. The flaw allows malicious actors to exploit this weakness remotely, posing a notable risk to users running version 0.14.0. The complexity involved in executing this attack is categorized as high, indicating that an attacker may require advanced skills and resources to successfully exploit the vulnerability. Although the vendor was alerted about the existence of this vulnerability, there has been no response, raising concerns about potential impacts on user security. It is crucial for organizations using flairNLP to assess their systems and implement necessary security measures to mitigate these risks.

Affected Version(s)

flair 0.14.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

runshen.gao (VulDB User)
.