Server-Side Prediction Vulnerability in MindsDB Platform Affects Versions 23.10.2.0 and Newer
CVE-2024-45853

7.5HIGH

Key Information:

Vendor

Mindsdb

Status
Vendor
CVE Published:
12 September 2024

What is CVE-2024-45853?

The MindsDB platform is vulnerable to deserialization of untrusted data, affecting versions 23.10.2.0 and newer. This flaw enables attackers to upload a malicious 'inhouse' model, which can execute arbitrary code on the server during predictive operations. This vulnerability emphasizes the need for rigorous validation of data inputs, especially in machine learning applications, to mitigate risks associated with arbitrary code execution.

Affected Version(s)

mindsdb 23.10.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.