CVE-2024-45855: High severity mindsdb vulnerability
Published Sep 12, 2024
·Updated
Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.
Affected Software
2 affected components
pip/mindsdb>=23.10.2.0<=24.9.2.1
MindsDB MindsDB>=23.10.2.0
Event History
Sep 12, 2024
CVE Published
via MITRE·01:04 PM
Data Sourced
via MITRE·01:04 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-45855?
CVE-2024-45855 is rated as a critical vulnerability due to its ability to allow arbitrary code execution on the server.
2
How do I fix CVE-2024-45855?
To remediate CVE-2024-45855, upgrade MindsDB to a version prior to 23.10.2.0, or ensure that untrusted data is not processed by the system.
3
What versions of MindsDB are affected by CVE-2024-45855?
CVE-2024-45855 affects MindsDB versions 23.10.2.0 and newer.
4
What is the impact of CVE-2024-45855 on my systems?
The impact of CVE-2024-45855 includes the potential for remote code execution and compromise of the server if exploited.
5
Who discovered CVE-2024-45855?
CVE-2024-45855 was disclosed by cybersecurity experts focusing on the MindsDB platform's security.