Arbitrary Code Execution Vulnerability in MindsDB Platform
CVE-2024-45855

7.5HIGH

Key Information:

Vendor

Mindsdb

Status
Vendor
CVE Published:
12 September 2024

What is CVE-2024-45855?

A deserialization vulnerability exists in the MindsDB platform, specifically in versions 23.10.2.0 and later. This flaw allows an attacker to upload a malicious 'inhouse' model that can execute arbitrary code on the server when the finetune operation is performed. Such exploits can compromise the integrity and security of the underlying system, leading to potential data breaches and unauthorized access.

Affected Version(s)

mindsdb 23.10.2.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.