CVE-2024-45853: High severity mindsdb vulnerability
Published Sep 12, 2024
·Updated
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.
Affected Software
2 affected components
pip/mindsdb>=23.10.2.0<=24.9.2.1
MindsDB MindsDB>=23.10.2.0
Event History
Sep 12, 2024
CVE Published
via MITRE·01:03 PM
Data Sourced
via MITRE·01:03 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-45853?
CVE-2024-45853 has a high severity due to the potential for remote code execution.
2
How do I fix CVE-2024-45853?
To fix CVE-2024-45853, upgrade the MindsDB platform to a version prior to 23.10.2.0.
3
Who is affected by CVE-2024-45853?
CVE-2024-45853 affects users of MindsDB versions 23.10.2.0 and newer.
4
What type of attack does CVE-2024-45853 enable?
CVE-2024-45853 enables an attacker to execute arbitrary code on the server through deserialization vulnerability.
5
What component of MindsDB is vulnerable in CVE-2024-45853?
The vulnerability in CVE-2024-45853 is related to the prediction functionality that uses uploaded models.