arbitrary code execution vulnerability in MindsDB platform
CVE-2024-45851

8.8HIGH

Key Information:

Vendor

Mindsdb

Status
Vendor
CVE Published:
12 September 2024

What is CVE-2024-45851?

A vulnerability exists in the MindsDB platform specifically between versions 23.10.5.0 and 24.7.4.1 when the Microsoft SharePoint integration is installed. This flaw allows for arbitrary code execution due to an improperly handled ā€˜INSERT’ query that can be crafted to execute Python code directly on the server. When databases are created using the SharePoint engine, a specially formulated query can bypass security mechanisms and be processed through an eval function, leading to potential exploitation of the server.

Affected Version(s)

mindsdb 23.10.5.0 < 24.7.4.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.