CVE-2024-10073 is a critical code injection vulnerability found in the ClusteringModel function within the flair/models/clustering.py file of flairNLP flair version 0.14.0. This flaw allows for remote code execution. While the attack complexity is high and exploitability is difficult, public exploit code exists. The CVSS score is 7.5 (HIGH), indicating significant impact (confidentiality, integrity, availability) if successfully exploited, though user interaction is required. Despite public disclosure, there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.14.0CPE matchmatch criteria | cpe:2.3:a:informatik.hu-berlin:flair:0.14.0:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.