Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xq5-54jp-2mfg

Опубликовано: 17 апр. 2025
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Rasa Pro Missing Authentication For Voice Connector APIs

Vulnerability

A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the credentials.yml file. This could allow an attacker to submit voice data to the Rasa Pro assistant from an unauthenticated source.

This impacts the following connectors:

  • audiocodes_stream
  • genesys
  • jambonz

As part of our investigation to resolve this issue, we have also performed a security review of our other voice channel connectors:

  • browser_audio: Does not support authentication. This is a development channel not intended for production use.
  • twilio_media_streams, twilio_voice and jambonz: Authentication is currently not supported by these channels, but our investigation has found a way for us to enable it for these voice channel connectors in a future Rasa Pro release.

Fix

The issue has been resolved for audiocodes, audiocodes_stream, and genesys connectors. Fixed versions of Rasa Pro have been released for 3.9.20, 3.10.19, 3.11.7 and 3.12.6. Please update to a fixed release.

If you are using one of the affected connectors, we strongly recommend upgrading to a fixed version. For connectors where authentication is not supported (e.g., Twilio), we suggest taking extra caution and considering other compensating controls if applicable.

Пакеты

Наименование

rasa-pro

pip
Затронутые версииВерсия исправления

>= 3.12.0, <= 3.12.5

3.12.6

Наименование

rasa-pro

pip
Затронутые версииВерсия исправления

>= 3.11.0, <= 3.11.6

3.11.7

Наименование

rasa-pro

pip
Затронутые версииВерсия исправления

>= 3.10.0, <= 3.10.18

3.10.19

Наименование

rasa-pro

pip
Затронутые версииВерсия исправления

<= 3.9.17

3.9.20

EPSS

Процентиль: 23%
0.00075
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 6.5
nvd
10 месяцев назад

Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the credentials.yml file. This could allow an attacker to submit voice data to the Rasa Pro assistant from an unauthenticated source. This issue has been patched for audiocodes, audiocodes_stream, and genesys connectors in versions 3.9.20, 3.10.19, 3.11.7 and 3.12.6.

EPSS

Процентиль: 23%
0.00075
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-306