Arbitrary Code Execution Vulnerability in MindsDB Platform
CVE-2024-45847

8.8HIGH

Key Information:

Vendor

Mindsdb

Status
Vendor
CVE Published:
12 September 2024

What is CVE-2024-45847?

An arbitrary code execution vulnerability has been identified in the MindsDB platform, specifically in versions ranging from 23.11.4.2 up to 24.7.4.1. This issue arises when certain integrations are installed on the server. A malicious actor can exploit this vulnerability by executing a specially crafted 'UPDATE' query that includes Python code against a database created with a vulnerable integration engine. This crafted query is processed by the server's eval function, leading to the execution of the injected code, potentially compromising the server's security and integrity.

Affected Version(s)

mindsdb 23.11.4.2 < 24.7.4.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.