Description
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0113 | Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it. |
Github GHSA |
GHSA-fr9q-rgwq-g5r5 | MindsDB Deserialization of Untrusted Data vulnerability |
References
History
Thu, 12 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mindsdb
Mindsdb mindsdb |
|
| CPEs | cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mindsdb
Mindsdb mindsdb |
|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it. | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-09-12T17:04:48.086Z
Reserved: 2024-09-10T15:36:52.127Z
Link: CVE-2024-45855
Updated: 2024-09-12T17:00:04.404Z
Status : Analyzed
Published: 2024-09-12T13:15:15.143
Modified: 2024-09-16T18:03:27.970
Link: CVE-2024-45855
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA