Python Package Security Update Advisory (CVE-2024-49375)

Overview

We have released a security update that addresses a vulnerability in a Python package. Users of affected products are advised to update to the latest version.

 

Affected Products

 

CVE-2024-49375

RASA Versions: ~ 3.6.21 (excluded)
rasa-pro version: ~ 3.10.12 (excluded)
rasa-pro version: ~ 3.9.16 (excluded)
rasa-pro version: ~ 3.8.18 (excluded)

 

 

Resolved Vulnerabilities

Remote code execution vulnerability (CVE-2024-49375)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
 

 

CVE-2024-49375

RASA Version: 3.6.21
rasa-pro version: 3.10.12
rasa-pro version: 3.9.16
rasa-pro version: 3.8.18

 

 

References

[1] cve-2024-51941
https://www.cve.org/CVERecord?id=CVE-2024-51941
[2] Fix metrics issue
https://issues.apache.org/jira/browse/AMBARI-26202