Arbitrary Code Execution Vulnerability in MindsDB Platform
CVE-2024-45848

8.8HIGH

Key Information:

Vendor

Mindsdb

Status
Vendor
CVE Published:
12 September 2024

What is CVE-2024-45848?

An arbitrary code execution vulnerability exists in the MindsDB platform when it is integrated with ChromaDB. This issue arises in versions ranging from 23.12.4.0 to 24.7.4.1. The vulnerability allows remote attackers to execute arbitrary Python code on the server through a specially crafted 'INSERT' query targeting a database created with the ChromaDB engine. When such a query is processed, the injected code can be passed to an eval function without adequate validation, posing significant security risks to the integrity and confidentiality of the affected systems.

Affected Version(s)

mindsdb 23.12.4.0 < 24.7.4.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.