GHSL-2023-182: _GHSL-2023-184: Server-side request forgery (SSRF), arbitrary file write and limited file write vulnerabilities in mindsdb/mindsdb - CVE-2023-49795, CVE-2023-50731, CVE-2023-49796
Published Dec 21, 2023
·Updated
Three vulnerabilities that can be exploited by unauthenticated users were found in MindsDB: a Server-side request forgery (SSRF) vulnerability, an arbitrary file write vulnerability and a limited file write vulnerability.
Affected Software
1 affected component
MindsDB MindsDB
Event History
Dec 21, 2023
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2023-184?
The severity of GHSL-2023-184 is rated at 78.
2
How do I fix GHSL-2023-184?
To fix GHSL-2023-184, update MindsDB to the latest version that addresses these vulnerabilities.
3
What types of vulnerabilities are identified in GHSL-2023-184?
GHSL-2023-184 includes Server-side request forgery (SSRF), arbitrary file write, and limited file write vulnerabilities.
4
Can unauthenticated users exploit GHSL-2023-184?
Yes, GHSL-2023-184 can be exploited by unauthenticated users.
5
What software is affected by GHSL-2023-184?
The affected software is MindsDB, specifically the MindsDB application.