Code Injection Vulnerability in flairNLP's ClusteringModel Function
CVE-2024-10073
What is CVE-2024-10073?
A significant code injection vulnerability has been discovered in flairNLP's flair product, specifically within the ClusteringModel function of the Mode File Loader component. The flaw allows malicious actors to exploit this weakness remotely, posing a notable risk to users running version 0.14.0. The complexity involved in executing this attack is categorized as high, indicating that an attacker may require advanced skills and resources to successfully exploit the vulnerability. Although the vendor was alerted about the existence of this vulnerability, there has been no response, raising concerns about potential impacts on user security. It is crucial for organizations using flairNLP to assess their systems and implement necessary security measures to mitigate these risks.
Affected Version(s)
flair 0.14.0
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
