MindsDB Platform Vulnerability Allows Malicious Models to Run Arbitrary Code
CVE-2024-45852

8.8HIGH

Key Information:

Vendor

Mindsdb

Status
Vendor
CVE Published:
12 September 2024

What is CVE-2024-45852?

The MindsDB platform has a vulnerability that allows for the deserialization of untrusted data, specifically in versions 23.3.2.0 and newer. This flaw can be exploited when a malicious user uploads a compromised model. If the server interacts with this malicious model, it can potentially execute arbitrary code, posing serious risks to the integrity and security of the server. Mitigating this vulnerability is crucial for maintaining robust security measures and protecting against unauthorized access.

Affected Version(s)

mindsdb 23.3.2.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.