MindsDB Platform Vulnerability Allows for Bypass of Server-Side Request Forgery Protection
CVE-2024-24759
9.1CRITICAL
Key Information
- Vendor
- MindsDB
- Status
- Mindsdb
- Vendor
- CVE Published:
- 5 September 2024
Summary
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.
CVSS V3.1
Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published.
Collectors
NVD Database