CVE-2024-45852: High severity mindsdb vulnerability
Published Sep 12, 2024
·Updated
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.
Affected Software
2 affected components
pip/mindsdb>=23.3.2.0<=24.9.2.1
MindsDB MindsDB>=23.3.2.0
Event History
Sep 12, 2024
CVE Published
via MITRE·01:02 PM
Data Sourced
via MITRE·01:02 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-45852?
CVE-2024-45852 is classified as a high severity vulnerability due to its potential to allow arbitrary code execution on the server.
2
How do I fix CVE-2024-45852?
To mitigate CVE-2024-45852, upgrade your MindsDB platform to version 24.9.2.1 or newer.
3
Which versions of MindsDB are affected by CVE-2024-45852?
Versions 23.3.2.0 and newer of the MindsDB platform are affected by CVE-2024-45852.
4
What are the risks associated with CVE-2024-45852?
CVE-2024-45852 poses risks such as unauthorized code execution and possible system compromise due to deserialization of untrusted data.
5
Can CVE-2024-45852 be exploited remotely?
Yes, CVE-2024-45852 can be exploited remotely if the vulnerable MindsDB platform is accessible from the internet.