Arbitrary Code Execution Vulnerability in MindsDB Platform
CVE-2024-45848
8.8HIGH
What is CVE-2024-45848?
An arbitrary code execution vulnerability exists in the MindsDB platform when it is integrated with ChromaDB. This issue arises in versions ranging from 23.12.4.0 to 24.7.4.1. The vulnerability allows remote attackers to execute arbitrary Python code on the server through a specially crafted 'INSERT' query targeting a database created with the ChromaDB engine. When such a query is processed, the injected code can be passed to an eval function without adequate validation, posing significant security risks to the integrity and confidentiality of the affected systems.
Affected Version(s)
mindsdb 23.12.4.0 < 24.7.4.1