PT-2024-6366 · Microsoft · Sharepoint Server

Kasimir Schulz

+2

·

Published

2024-09-10

·

Updated

2024-09-16

·

CVE-2024-45850

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MindsDB versions 23.10.5.0 through 24.7.4.1
Description An arbitrary code execution issue exists when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, a specially crafted INSERT query containing Python code can be used to execute code on the server. This occurs because the code is passed to an eval function. The vulnerability is related to incorrect code generation management in the eval function of the MindsDB platform, allowing a remote attacker to execute arbitrary code by injecting a specially crafted INSERT query.
Recommendations For MindsDB versions 23.10.5.0 through 24.7.4.1, consider disabling the Microsoft SharePoint integration until a patch is available to prevent exploitation. As a temporary workaround, restrict the use of INSERT queries against databases created with the SharePoint engine to minimize the risk of arbitrary code execution. Avoid using the eval function in the MindsDB platform until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Eval Injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07408
CVE-2024-45850
GHSA-V6G6-3CM3-VF6C
PYSEC-2024-80

Affected Products

Sharepoint Server