Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4jcv-vp96-94xr | MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding |
Thu, 05 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mindsdb
Mindsdb mindsdb |
|
| CPEs | cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mindsdb
Mindsdb mindsdb |
|
| Metrics |
ssvc
|
Thu, 05 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service. Version 23.12.4.2 contains a patch. | |
| Title | MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-09-05T17:46:08.516Z
Reserved: 2024-01-29T20:51:26.010Z
Link: CVE-2024-24759
Updated: 2024-09-05T17:46:02.784Z
Status : Analyzed
Published: 2024-09-05T17:15:12.380
Modified: 2024-09-06T13:06:18.623
Link: CVE-2024-24759
No data.
OpenCVE Enrichment
No data.
Github GHSA