PT-2024-20536 · Mindsdb · Mindsdb

Sim4N6

·

Published

2024-09-05

·

Updated

2024-10-14

·

CVE-2024-24759

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions MindsDB versions prior to 23.12.4.2
Description MindsDB is a platform for building artificial intelligence from enterprise data. A threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding, which can also lead to denial of service.
Recommendations For versions prior to 23.12.4.2, update to version 23.12.4.2 to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable API endpoints to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2024-24759
GHSA-4JCV-VP96-94XR
PYSEC-2024-74

Affected Products

Mindsdb