CVE-2024-45856: XSS
Published Sep 12, 2024
·Updated
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.
Affected Software
2 affected components
pip/mindsdb<=24.9.2.1
MindsDB MindsDB
Event History
Sep 12, 2024
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·03:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-45856?
CVE-2024-45856 is classified as a high severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2024-45856?
To fix CVE-2024-45856, upgrade to MindsDB version 24.9.2.2 or later, which addresses the XSS vulnerability.
3
What versions of MindsDB are affected by CVE-2024-45856?
All versions of MindsDB up to and including 24.9.2.1 are affected by CVE-2024-45856.
4
What types of attacks can CVE-2024-45856 facilitate?
CVE-2024-45856 can facilitate attacks such as unauthorized JavaScript execution in the web UI.
5
Is CVE-2024-45856 specific to any platform or software?
CVE-2024-45856 specifically affects the MindsDB platform across all versions.