PT-2023-31353 · Mindsdb · Mindsdb

Sylwia-Budzynska

·

Published

2023-12-11

·

Updated

2023-12-14

·

CVE-2023-49795

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions MindsDB versions prior to 23.11.4.1
Description MindsDB connects artificial intelligence models to real-time data. The issue is related to a server-side request forgery vulnerability in the file.py module. This can lead to limited information disclosure, allowing for the retrieval of files with specific extensions and potentially scanning internal networks for open ports or existing files. The vulnerability is due to the lack of validation of user-controlled URLs in the source variable, which can be used to create arbitrary requests.
Recommendations For versions prior to 23.11.4.1, use MindsDB's staging branch or update to version 23.11.4.1, which contains a fix for the issue. As a temporary workaround, consider restricting access to the file.py module or disabling the functionality that uses the source variable until a patch is applied.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2023-49795
GHSA-34MR-6Q8X-G9R6
PYSEC-2023-277

Affected Products

Mindsdb