MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4jcv-vp96-94xr MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 05 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Mindsdb
Mindsdb mindsdb
CPEs cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:*
Vendors & Products Mindsdb
Mindsdb mindsdb
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
Description MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.
Title MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-09-05T17:46:08.516Z

Reserved: 2024-01-29T20:51:26.010Z

Link: CVE-2024-24759

cve-icon Vulnrichment

Updated: 2024-09-05T17:46:02.784Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-05T17:15:12.380

Modified: 2024-09-06T13:06:18.623

Link: CVE-2024-24759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.