Description
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0110 | Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with. |
Github GHSA |
GHSA-7vhj-pfwv-hx3w | MindsDB Deserialization of Untrusted Data vulnerability |
References
History
Thu, 12 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mindsdb
Mindsdb mindsdb |
|
| CPEs | cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mindsdb
Mindsdb mindsdb |
|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with. | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-09-12T17:15:03.659Z
Reserved: 2024-09-10T15:36:52.127Z
Link: CVE-2024-45852
Updated: 2024-09-12T17:14:51.345Z
Status : Analyzed
Published: 2024-09-12T13:15:14.403
Modified: 2024-09-16T17:51:04.233
Link: CVE-2024-45852
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA