CVE-2024-45847: Code Injection
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPDATE’ query containing Python code is run against a database created with the specified integration engine, the code will be passed to an eval function and executed on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45847?
CVE-2024-45847 is classified as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-45847?
To fix CVE-2024-45847, upgrade MindsDB to version 24.7.4.2 or later.
What versions are affected by CVE-2024-45847?
CVE-2024-45847 affects MindsDB versions from 23.11.4.2 up to 24.7.4.1.
What type of vulnerability is CVE-2024-45847?
CVE-2024-45847 is an arbitrary code execution vulnerability.
In which scenarios can CVE-2024-45847 be exploited?
CVE-2024-45847 can be exploited when a specially crafted 'UPDATE' query containing Python code is executed on a database with specific integrations.