Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdb
CVE-2023-30620
7.5HIGH
What is CVE-2023-30620?
An unsafe extraction vulnerability has been identified in the MindsDB Machine Learning platform, arising from the use of tarfile.extractall()
when processing remotely retrieved tarballs. This flaw can allow an attacker to overwrite any local file that the server process can access, leading to potentially significant damage. Notably, there is no risk of file exposure associated with this vulnerability. It is imperative for users to upgrade to version 23.2.1.0 or later to mitigate this issue, as there are no known workarounds.
Affected Version(s)
mindsdb < 23.2.1.0