Description
MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB's `staging` branch or v23.11.4.1, which contain a fix for the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-0149 | MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB's `staging` branch or v23.11.4.1, which contain a fix for the issue.\n |
Github GHSA |
GHSA-34mr-6q8x-g9r6 | Server-Side Request Forgery in mindsdb |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T22:01:26.010Z
Reserved: 2023-11-30T13:39:50.863Z
Link: CVE-2023-49795
No data.
Status : Modified
Published: 2023-12-11T19:15:09.070
Modified: 2024-11-21T08:33:51.503
Link: CVE-2023-49795
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA