MindsDBGHSA-9gq6-6936-885w
MindsDB Eval Injection vulnerability
High8.8CVE-2024-45848 · Published Sep 12, 2024 · updated Sep 16, 2024
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mindsdb PyPI | >= 23.12.4.0, < 24.7.4.1 | 24.7.4.1 |
Details and references
An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT’ query containing Python code is run against a database created with the ChromaDB engine, the code will be passed to an eval function and executed on the server.
More MindsDB advisories
All MindsDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 122024 | MindsDB Eval Injection vulnerability CVE-2024-45849High8.8fixed in 24.7.4.1 | High8.8 | 24.7.4.1 |
| Sep 122024 | MindsDB Eval Injection vulnerability CVE-2024-45847High8.8fixed in 24.7.4.1 | High8.8 | 24.7.4.1 |
| Sep 122024 | MindsDB Eval Injection vulnerability CVE-2024-45850High8.8fixed in 24.7.4.1 | High8.8 | 24.7.4.1 |
| Sep 122024 | MindsDB Eval Injection vulnerability CVE-2024-45846High8.8fixed in 24.7.4.1 | High8.8 | 24.7.4.1 |
| Sep 122024 | MindsDB Cross-site Scripting vulnerability CVE-2024-45856Medium9.0no fix yet | Medium9.0 | No fix yet |
| Sep 122024 | MindsDB Deserialization of Untrusted Data vulnerability CVE-2024-45854High7.1no fix yet | High7.1 | No fix yet |