Arbitrary Code Execution Vulnerability in MindsDB Platform
CVE-2024-45847
What is CVE-2024-45847?
An arbitrary code execution vulnerability has been identified in the MindsDB platform, specifically in versions ranging from 23.11.4.2 up to 24.7.4.1. This issue arises when certain integrations are installed on the server. A malicious actor can exploit this vulnerability by executing a specially crafted 'UPDATE' query that includes Python code against a database created with a vulnerable integration engine. This crafted query is processed by the server's eval function, leading to the execution of the injected code, potentially compromising the server's security and integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
mindsdb 23.11.4.2 < 24.7.4.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
