CVE-2024-45848: Code Injection
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT’ query containing Python code is run against a database created with the ChromaDB engine, the code will be passed to an eval function and executed on the server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45848?
CVE-2024-45848 is classified as a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-45848?
To fix CVE-2024-45848, upgrade MindsDB to version 24.7.4.2 or later.
Which versions of MindsDB are affected by CVE-2024-45848?
Versions 23.12.4.0 up to 24.7.4.1 of MindsDB are affected by CVE-2024-45848 when the ChromaDB integration is installed.
What kind of vulnerability is CVE-2024-45848?
CVE-2024-45848 is an arbitrary code execution vulnerability resulting from improperly handling specially crafted 'INSERT' queries.
Does CVE-2024-45848 affect all users of MindsDB?
CVE-2024-45848 specifically affects users who have installed the ChromaDB integration on affected versions of the MindsDB platform.