Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0111 | Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction. |
Github GHSA |
GHSA-q9r8-89xr-4xv4 | MindsDB Deserialization of Untrusted Data vulnerability |
Thu, 12 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mindsdb
Mindsdb mindsdb |
|
| CPEs | cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mindsdb
Mindsdb mindsdb |
|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction. | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-09-12T17:13:52.469Z
Reserved: 2024-09-10T15:36:52.127Z
Link: CVE-2024-45853
Updated: 2024-09-12T17:13:33.502Z
Status : Analyzed
Published: 2024-09-12T13:15:14.643
Modified: 2024-09-16T17:59:03.427
Link: CVE-2024-45853
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA