CVE-2024-45846: Code Injection
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SELECT WHERE’ clause containing Python code is run against a database created with the Weaviate engine, the code will be passed to an eval function and executed on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45846?
CVE-2024-45846 is classified as an arbitrary code execution vulnerability, which is considered critical due to the potential for exploitation.
How do I fix CVE-2024-45846?
To remediate CVE-2024-45846, upgrade the MindsDB platform to version 24.7.4.2 or higher, as it resolves the vulnerability.
Which versions of MindsDB are affected by CVE-2024-45846?
CVE-2024-45846 affects MindsDB versions from 23.10.3.0 up to and including 24.7.4.1.
What is the impact of exploiting CVE-2024-45846?
Exploiting CVE-2024-45846 allows an attacker to execute arbitrary Python code on the server, posing severe security risks.
Is there a workaround for CVE-2024-45846?
There are no recommended workarounds for CVE-2024-45846, making it critical to upgrade to a secure version.