Vulnerability Description
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mindsdb | Mindsdb | < 23.12.4.2 |
Related Weaknesses (CWE)
References
- https://github.com/mindsdb/mindsdb/commit/5f7496481bd3db1d06a2d2e62c0dce960a1fe1Patch
- https://github.com/mindsdb/mindsdb/security/advisories/GHSA-4jcv-vp96-94xrExploitVendor Advisory
FAQ
What is CVE-2024-24759?
CVE-2024-24759 is a vulnerability with a CVSS score of 9.3 (CRITICAL). MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website w...
How severe is CVE-2024-24759?
CVE-2024-24759 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-24759?
Check the references section above for vendor advisories and patch information. Affected products include: Mindsdb Mindsdb.