CVE-2023-49795: GHSL-2023-182_GHSL-2023-184: Server-side request forgery (SSRF), arbitrary file write and limited file write vulnerabilities in mindsdb/mindsdb - CVE-2023-49795, CVE-2023-50731, CVE-2023-49796

Published Dec 11, 2023
·
Updated

Impact

The put method in mindsdb/mindsdb/api/http/namespaces/file.py does not validate the user-controlled URL in the source variable and uses it to create arbitrary requests on line 115, which allows Server-side request forgery (SSRF). This issue may lead to Information Disclosure. The SSRF allows for forging arbitrary network requests from the MindsDB server. It can be used to scan nodes in internal networks for open ports that may not be accessible externally, as well as scan for existing files on the internal network. It allows for retrieving files with csv, xls, xlsx, json or parquet extensions, which will be viewable via MindsDB GUI. For any other existing files, it is a blind SSRF. Patches

Use mindsdb staging branch or v23.11.4.1

References

GHSL-2023-182 SSRF prevention cheatsheet.

Other sources

MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in file.py. This can lead to limited information disclosure. Users should use MindsDB's staging branch or v23.11.4.1, which contain a fix for the issue.

MITRE

Three vulnerabilities that can be exploited by unauthenticated users were found in MindsDB: a Server-side request forgery (SSRF) vulnerability, an arbitrary file write vulnerability and a limited file write vulnerability.

GitHub Security Lab

Affected Software

2 affected componentsFixes available
pip/mindsdb<23.11.4.1
23.11.4.1
MindsDB MindsDB<23.11.4.1

Event History

Dec 11, 2023
CVE Published
via MITRE·07:01 PM
Data Sourced
via MITRE·07:01 PM
DescriptionSeverityWeakness
Dec 12, 2023
Advisory Published
via GitHub·12:48 AM
Dec 21, 2023
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-49795?

CVE-2023-49795 is classified as a high severity vulnerability due to its potential for server-side request forgery (SSRF).

2

How do I fix CVE-2023-49795?

To fix CVE-2023-49795, upgrade to MindsDB version 23.11.4.1 or later, which addresses the vulnerability.

3

What type of vulnerability is CVE-2023-49795?

CVE-2023-49795 is a server-side request forgery (SSRF) vulnerability.

4

Which versions of MindsDB are affected by CVE-2023-49795?

MindsDB versions prior to 23.11.4.1 are affected by CVE-2023-49795.

5

What actions are at risk due to CVE-2023-49795?

CVE-2023-49795 allows attackers to create arbitrary requests, which may lead to leakage of sensitive information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203