Skip to content
MindsDBGHSA-j8w6-2r9h-cxhj

GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182

High9.1CVE-2023-50731 · Published Dec 15, 2023 · updated Nov 22, 2024

### Impact Issue: Arbitrary file write in file.py (GHSL-2023-183) ### Patches Use mindsdb staging branch or v23.11.4.1

GitHub advisory

Affected versions

PackageAffectedFixed in
mindsdb
PyPI
< 23.11.4.123.11.4.1
Details and references

More MindsDB advisories

All MindsDB
Advisory
Cross-site Scripting (XSS) in mindsdb/mindsdb
Medium5.8Apr 16, 2024
Improper Input Validation in mindsdb
Medium5.3Dec 12, 2023
Server-Side Request Forgery in mindsdb
Medium6.5Dec 12, 2023
MindsDB can be made to not verify SSL certificates
Critical9.1Aug 1, 2023
mindsdb arbitrary file write when extracting a remotely retrieved Tarball
High7.5Mar 30, 2023
Arbitrary file write in mindsdb when Extracting Tarballs retrieved from a remote location
Medium8.5Mar 30, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.