Skip to content
MindsDBGHSA-q9r8-89xr-4xv4

MindsDB Deserialization of Untrusted Data vulnerability

High7.1CVE-2024-45853 · Published Sep 12, 2024 · updated Sep 16, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
mindsdb
PyPI
>= 23.10.2.0, <= 24.9.2.1No fix yet
Details and references

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-502
Also known as
CVE-2024-45853, PYSEC-2024-83

More MindsDB advisories

All MindsDB
DateAdvisory
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45848High8.8fixed in 24.7.4.1
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45849High8.8fixed in 24.7.4.1
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45847High8.8fixed in 24.7.4.1
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45850High8.8fixed in 24.7.4.1
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45846High8.8fixed in 24.7.4.1
Sep 122024MindsDB Cross-site Scripting vulnerability
CVE-2024-45856Medium9.0no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.