MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0146 | MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests library. In version 23.7.4.0, certificates are validated by default, which is the desired behavior. |
Github GHSA |
GHSA-8hx6-qv6f-xgcw | MindsDB can be made to not verify SSL certificates |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-03T18:11:45.928Z
Reserved: 2023-07-24T16:19:28.365Z
Link: CVE-2023-38699
Updated: 2024-08-02T17:46:56.667Z
Status : Modified
Published: 2023-08-04T18:15:15.797
Modified: 2024-11-21T08:14:04.857
Link: CVE-2023-38699
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA