Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2700 | A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI. |
Github GHSA |
GHSA-32fj-r8qw-r8w8 | MindsDB Cross-site Scripting vulnerability |
Thu, 12 Sep 2024 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mindsdb
Mindsdb mindsdb |
|
| CPEs | cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mindsdb
Mindsdb mindsdb |
|
| Metrics |
ssvc
|
Thu, 12 Sep 2024 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2024-09-12T16:57:45.128Z
Reserved: 2024-09-10T15:36:55.926Z
Link: CVE-2024-45856
Updated: 2024-09-12T16:57:37.138Z
Status : Analyzed
Published: 2024-09-12T13:15:15.373
Modified: 2024-09-16T18:04:07.503
Link: CVE-2024-45856
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA