PT-2023-31353 · Mindsdb · Mindsdb

·

CVE-2023-49795

·

Publicado

2023-12-11

·

Atualizado

2023-12-14

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MindsDB versions prior to 23.11.4.1
Description MindsDB connects artificial intelligence models to real-time data. The issue is related to a server-side request forgery vulnerability in the file.py module. This can lead to limited information disclosure, allowing for the retrieval of files with specific extensions and potentially scanning internal networks for open ports or existing files. The vulnerability is due to the lack of validation of user-controlled URLs in the source variable, which can be used to create arbitrary requests.
Recommendations For versions prior to 23.11.4.1, use MindsDB's staging branch or update to version 23.11.4.1, which contains a fix for the issue. As a temporary workaround, consider restricting access to the file.py module or disabling the functionality that uses the source variable until a patch is applied.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-49795
GHSA-34MR-6Q8X-G9R6
PYSEC-2023-277

Produtos afetados

Mindsdb