PT-2024-31809 · Mindsdb · Mindsdb
Published
2024-09-12
·
Updated
2024-09-16
·
CVE-2024-45852
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
MindsDB versions 23.3.2.0 and newer
Description:
The issue concerns the deserialization of untrusted data in the MindsDB platform. This allows a maliciously uploaded model to run arbitrary code on the server when interacted with.
Recommendations:
For MindsDB versions 23.3.2.0 and newer, consider restricting the upload of models to trusted sources until a patch is available. As a temporary workaround, disabling the interaction with uploaded models can minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mindsdb