Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdb
CVE-2023-30620

7.5HIGH

Key Information:

Vendor

Mindsdb

Status
Vendor
CVE Published:
21 April 2023

What is CVE-2023-30620?

An unsafe extraction vulnerability has been identified in the MindsDB Machine Learning platform, arising from the use of tarfile.extractall() when processing remotely retrieved tarballs. This flaw can allow an attacker to overwrite any local file that the server process can access, leading to potentially significant damage. Notably, there is no risk of file exposure associated with this vulnerability. It is imperative for users to upgrade to version 23.2.1.0 or later to mitigate this issue, as there are no known workarounds.

Affected Version(s)

mindsdb < 23.2.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.