Skip to content
MindsDBGHSA-crhp-7c74-cg4c

Improper Input Validation in mindsdb

Medium5.3CVE-2023-49796 · Published Dec 12, 2023 · updated Nov 22, 2024

### Impact The put method in `mindsdb/mindsdb/api/http/namespaces/file.py` does not validate the user-controlled `name` value, which is used in a temporary file name, which is afterwards opened for writing on lines 122-125, which leads to path injection. This issue may lead to arbitrary file write. This vulnerability allows for writing files anywhere on the server that the filesystem permissions that the running server has access to. ### Patches Use mindsdb staging branch or v23.11.4.1 ### References * GHSL-2023-184 * See [CodeQL path injection prevention guidelines](https://codeql.github.com/codeql-query-help/python/py-path-injection/) and [OWASP guidelines](https://owasp.org/www-community/attacks/Path_Traversal).

GitHub advisory

Affected versions

PackageAffectedFixed in
mindsdb
PyPI
< 23.11.4.123.11.4.1
Details and references

More MindsDB advisories

All MindsDB
Advisory
Cross-site Scripting (XSS) in mindsdb/mindsdb
Medium5.8Apr 16, 2024
GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182
High9.1Dec 15, 2023
Server-Side Request Forgery in mindsdb
Medium6.5Dec 12, 2023
MindsDB can be made to not verify SSL certificates
Critical9.1Aug 1, 2023
mindsdb arbitrary file write when extracting a remotely retrieved Tarball
High7.5Mar 30, 2023
Arbitrary file write in mindsdb when Extracting Tarballs retrieved from a remote location
Medium8.5Mar 30, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.