Логотип exploitDog
bind:CVE-2025-32377
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-32377

Количество 2

Количество 2

nvd логотип

CVE-2025-32377

10 месяцев назад

Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the credentials.yml file. This could allow an attacker to submit voice data to the Rasa Pro assistant from an unauthenticated source. This issue has been patched for audiocodes, audiocodes_stream, and genesys connectors in versions 3.9.20, 3.10.19, 3.11.7 and 3.12.6.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7xq5-54jp-2mfg

10 месяцев назад

Rasa Pro Missing Authentication For Voice Connector APIs

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-32377

Rasa Pro is a framework for building scalable, dynamic conversational AI assistants that integrate large language models (LLMs). A vulnerability has been identified in Rasa Pro where voice connectors in Rasa Pro do not properly implement authentication even when a token is configured in the credentials.yml file. This could allow an attacker to submit voice data to the Rasa Pro assistant from an unauthenticated source. This issue has been patched for audiocodes, audiocodes_stream, and genesys connectors in versions 3.9.20, 3.10.19, 3.11.7 and 3.12.6.

CVSS3: 6.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-7xq5-54jp-2mfg

Rasa Pro Missing Authentication For Voice Connector APIs

CVSS3: 6.5
0%
Низкий
10 месяцев назад

Уязвимостей на страницу